I need to route specific messages that come into Splunk to another destination via syslog. I have the props/transforms, but need help with the REGEX. I need to send any event that has "Session started" or "Session ended". Not sure how to wildcard that...