I have one sourcetype that does not allow me to create a static field extraction, because we have several fields with different name and is almost impossible to cover all of them.
My data is similar to this:
fieldname1 : values1 with spaces - fieldname2 : value2 - fieldname3 : value-for-field3
field name4 : values4withoutspaces - fieldname5 : value5 (this should be included in value5) - fieldname6 : value-for-field3 fieldname7 :
All kv pairs are delimitd by " - " and the pair delimiter is " : " .
To cover this requirement, I have a field transforms that uses a regex to calculate key-value pairs automatically
CLEAN_KEYS = 0
FORMAT = $1::$2
REGEX = (\S+)\s:\s(\S+)
PROBLEM: When the field name or the value has spaces, I can not get the full values.
Could some, more experienced than me, help me with my regex expression, please?