I have logs from a windows server that are stored as text, Logscape seams to treat every line of the text as new record even if several lines belong to the same record (event)
I'm trying to solve the issue creating a new data type, since each record is wrapped in curly brackets and I'm trying to use a regex expression
but I'm having problems with Logscape as it just looks at each single line so it cannot find any match
I have tried
\{*\}
Or
\{([^}]*)\}
Logscape says that there are no matches because it looks just at each single line, where my record is split on several lines
Hey mark,
The line breaking is part of the datasource configuration. You would need to change the line breaking rule to be 'Explicit' (datasource->advanced) and set the entry to use '{'.
This will tell the indexer to break on lines beginning with '{' and fix the parsing problem you are seeing.