i have a longish regex to weed out pertinent fields from some asa output. they generally follow the same format, however, sometimes the lines have say the protocol located in one place but sometimes in other.
if i were to construct the inline regex to have multiple
(?P<proto>\w+) blah (?P<proto>\w+)
then i get
Encountered the following error while trying to update: In handler 'props-extract': Regex: two named subpatterns have the same name
which makes sense; but couldn't the inline field extraction just create multi-value fields?
i can't really use a transform as i want context on the field; eg src_ip and dst_ip - of which depends on the relative location of the ip address in the regex.
any ideas? does it make sense to allow multi-value field extraction with inline regexes?