Event Management - Event Rules - Regex Parser How-ToIssue <!-- div.margin{ padding: 10px 40px 40px 30px; } table.tocTable{ border: 1px solid; border-color:#E0E0E0; background-color: rgb(245, 245, 245); padding-top: .6em; padding-bottom: .6em; padding-left: .9em; padding-right: .6em; } table.noteTable{ border:1px solid; border-color:#E0E0E0; background-color: rgb(245, 245, 245); width: 100%; border-spacing:2; } table.internaltable { white-space:nowrap; text-align:left; border-width: 1px; border-collapse: collapse; font-size:14px; width: 85%; } table.internaltable th { border-width: 1px; padding: 5px; border-style: solid; border-color: rgb(245, 245, 245); background-color: rgb(245, 245, 245); } table.internaltable td { border-width: 1px; padding: 5px; border-style: solid; border-color: #E0E0E0; color: #000000; } .title { color: #D1232B; font-weight:normal; font-size:28px; } h1{ color: #D1232B; font-weight:normal; font-size:21px; margin-bottom:-5px } h2{ color: #646464; font-weight:bold; font-size:18px; } h3{ color: #000000; font-weight:BOLD; font-size:16px; text-decoration:underline; } h4{ color: #646464; font-weight:BOLD; font-size:15px; text-decoration:; } h5{ color: #000000; font-weight:BOLD; font-size:13px; text-decoration:; } h6{ color: #000000; font-weight:BOLD; font-size:14px; text-decoration:; } ul{ list-style: disc outside none; margin-left: 0; } li { padding-left: 1em; } --> How to use Event Rules Regex Parser Description This article is intended to help clarify some of the particulars and limitations regarding the Regex Parser Solution Flags cannot be manually set. By default multi-line is not set, single-line is.The following features are not currently supported: Setting flagsLookbacks Example of how to parse a multi-line event (working example vs. non-working examples): em_event Description:"Stuff: StuffValue: some valueTarget Hostname: domain.testing.comTarget IP Address: 10.10.1.1" Configure Event Rule to parse Description with:"Hostname: (.*\n)" - Evaluation error (requires full text match)"(.+?(?<=Hostname: ))(.+?$)(.*)" - Evaluation error (Lookback not supported)"(?m)(.+Hostname: )(.+?$)(.*)" - Evaluation error (Manual flags not supported)"(.+Hostname: )(.+?)(\n.*)" - Works This will usually result in unwanted/unneeded capture groups. This is expected and you will just need to ignore using those capture groups for the Event Rules transform page. Applicable Versions Post-Geneva Additional Information Java regex tester: https://www.freeformatter.com/java-regex-tester.html