I am trimming my extractors. I found the following regex extractor for Windows XML log format to consume a bit of resources (due to backtracking, I guess):
This one seems to sometime take quite a long time (like 2 seconds) to finish. What would be the most efficient way to extract the contents of the Message field. I did not find an XML extractor in Graylog, that would just grab everything within the tags, so I guess some other extractor type or regex expression would be better.
I am not sure if the log content had the < or > characters within these tags, so I am a bit reluctant to use the regex: