my raw event in splunk looks like field1="223" field2="333" event="some text text2 text3 something something2"
can you add to this regular formula part, which whill parse field event?
I mean event="..."
Your requirement is ambiguous. Do you want to include the spaces between words in your count of "three spaces"? Or do you want everything before three consecutive spaces? Also, the carat is in the wrong place when you have put it in an expression, try it this way