My events look like this
Event1: blah blah - blah blah ANY CHARACTERS
(multilines could exist after the first lines and sometime my event is with a single line)
Event 2: blah blah .... - blah blah
How to extract from character "-" till the end of the first line, how to do that?.
I have tried (?\
n) but my second event didn't appear with single line.
This is the solution:
(?P\r\n]+)
Didn't this work?
http://splunk-base.splunk.com/answers/83324/can-i-write-a-conditional-regular-expression
Questions/observations:
By ANY CHARACTER, I assume that includes dashes/hyphens as well?
Don't you want \s-\s(?<your_field>.*)$
(remember that the dollar sign is the end of the line)
Please post some real events.
/K
Thanks for the suggestion it is the right answer \s-\s(?
The extraction that you suggested is working well, Great
ok, This is great also
(?P