I am using splunk free -- and have data in format of:
2019-06-06 11:10:10,029 "somedata" # - Start of event TransId=(?\d+) # - I want to capture this value
- Logging More data on next line PaymendId=(?\d+) #I want to capture this value -- End of event 2019-06-06 11:10:10,129 "somedata" - then next event with different logging info.
What needs to be set in the source type for this to work?
I was not able to create multi-line field exaction, I did use (?ms) but had no success.
Thanks for any help or suggestions.