hi i have the following logs
@2013-03-25 17:29:36,634||FINE|CXI|15553|Session=kksrrdica24v-2013084212936-1|CXI Diagnostic: (Interpreter::log_element) |kksrrdica24v####
@2013-03-25 17:29:11,923||FINE|CXI|15339|Session=kksrrdica24v-2013084212901-1|CXI Diagnostic: (Interpreter::log_element) |kksrrdica24v####
Out of it i want to extract (Interpreter::log_element) <label='app_begin', expr='CCA:init:connection.alerting, APP-BEGIN: from first log and (Interpreter::log_element) <label='app_end', expr='CCA:end:execute_end, APP-END: from second log
when i tried IFE by giving the above mentioned example values for a field it splited (Interpreter::log_element) <label='app_begin', expr='CCA:init:connection.alerting, APP-BEGIN: into 3 separate fields because of "," in between the string and showing regex as (?:[^ \n]* ){2}(?P [^,]+),(?P [^,]+),(?P \s+\w+-\w+:)
Can some one help on this how the regex can be modified so that it will be considered whole string as one field.
... View more