Oh, you are right. I had run so many tests yesterday that it was getting a little confusing. I've tried both variants, with the same regex: [example]
REGEX = (?<_KEY_1>([^=\"]+))=(?<_VAL_1>([^=\"]+)) and [example]
REGEX = ([^=\"]+)=([^=\"]+)
FORMAT = $1::$2 but I am only getting the value to the first whitespace. "key=val ue" will result in key=val with both variants. I've tested all changes in props.conf / transforms.conf under etc/system/local to ensure, that there is no other setting that is overwriting my tests. Maybe I should also mention that these value are embedded in some kind of pseudo json format. I am, however, not using indexed extractions. The events are looking something like this: {"severity":"info","time":"123456789","message":"key1=value1" "key2=val ue 2"}
... View more