I'm working on parsing a message from a syslog input.

If anyone else can help, I’d very much appreciate that as well.

I’m working on parsing a message from a syslog input. I have a long string that I need to break up. I need to discard some information from the field and am curious if there is a way to accomplish this. I’m trying to remove what’s highlighted.

I’m fairly certain it’s a ${GREEDYDATA:UNWANTED} but I can’t get it to work with any separators that I have tried.

Try to use %{USERNAME:user} instead.

You’re incredible, thank you.