[source::.../var/log/splunk/splunk_archiver.log(.\d+)?] EXTRACT-severity,logger = .*?(?[A-Z]+) ((?[^\s]+) \-)*