the message has at least 1 entry after the : and CAN HAVE up to x entries, which are separated with ",".
I need a grok which matches the first entry and also matches every optionally entry, separated by a "," all assigned to the field "entries".
is there no way with grok? this line is a part of a pattern and my filter consists of many many patterns. so I have to split this line in the pattern itself.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.