I have one sourcetype that has a common field, but it's located at different places in the event depending on the message type. I've defined regex and tested it successfully for the three messages types. However, when I try to add the three different regex's to props.conf with the same field name, only the first one gets processed. How can I define multiple regex patterns to extract the same field name in the same source type?
The field that I am trying to extract is an aircraft tail number: N999XY in the examples below.
Message Type #1
Nov 20 20:54:33 host.mydomain.net ACCT_INTERIM,N999XY,188.8.131.52,N999XY_20141120150929,AABBCCDDEEFF,184.108.40.206,1A6F9EB7-B4EF-46CD-BCA6-024DC4360C5D,HOTSPOT_6,12345678,1234567,
Regex for Type #1
Message Type #2
Nov 20 20:34:44 host.mydomain.net ACCESS-ACCEPT,0,220.127.116.11,N999XY_20141120185555,AABBCCDDEEFF,HOTSPOT_6,
Regex for Type #2
Message Type #3
Nov 20 20:40:49 host.mydomain.net DHCP_REQUEST,123456789,AABBCCDDEEFF,18.104.22.168,12345678,AA:BB:CC:DD:EE:FF@UNASSIGNED,N999XY,