1 Reply Latest reply on Nov 24, 2014 3:51 PM by alexander_h

    Creating multiple events from one log message




      Lets say that I have a syslog record like this:

      Nov 20 16:59:36 Server100 service111: "url:http://www.badlink.com, attributes:[Malware, Bad Location, No SSL]"

      And I have parser rules for each of the attributes(malware,bad location, no ssl), how can I create three different events for each match on the log. As it stands now it is only creating an event for the first attribute it sees and moves on to the next syslog entry.