How would I perform a Unix grep on a multi-line event? Ex.:
_raw="one
two
three"
_raw="tree
bee
eleven"
I'd like to apply something like the following to my search | eval _raw=grep(_raw, "ee") and get:
_raw="three"
_raw="tree
bee"
* I only have access to searching existing logs with multi-line events.
FYI: It is possible to split a multi-line event into a bunch of events and 'grep' the results with another | search. See: https://answers.splunk.com/comments/619554/view.html