============================================= Header ============================================= Sometimes there is header data before any delimiter is reached. That data can apply to all objects in the output json. 2 jobs submitted at Tue Nov 26 13:50:00 EST 2013 Jobs will be logged into database: Z_500_DB Super Order ID: 555 ============================================= Begin job log at Tue Nov 26 13:50:43 EST 2013 ============================================= This is just some random log file you might get from an application. job is a magical word timestamp: Tue Nov 26 13:50:43 EST 2013 JobID: 12345 email: abc@abc.com there are lots of things you might search for. Dude, we just ran this sql: SELECT * FROM TABLE WHERE 1=1; Here is some json we may want to extract: { "a" : 1, "b" : 2, "c" : 3 } a,b,c This thing sometimes happens: 1 2400 1 3000 some junk ERROR: Oops! There was a problem with this job. Elapsed time: 1000ms ============================================= End job log at Tue Nov 26 13:50:44 EST 2013 ============================================= sum log is 1 to many job logs concatenated together. ============================================= Begin job log at Tue Nov 26 13:51:43 EST 2013 ============================================= Foo log version: 2.0.1 This is just some random log file you might get from an application. job is a magical word timestamp: Tue Nov 26 13:51:43 EST 2013 JobID: 12346 email: def@abc.com there are lots of things you might search for. This can happen: A 1300 B 1000 Linux 9000 Dude, we just ran this sql: SELECT * FROM TABLE WHERE 1=1; Here is some json we may want to extract: { "a" : 1, "b" : 2, "c" : 3 } a,b,c This other thing can happen: 1 2400 1 3000 some junk Elapsed time: 1001ms ============================================= End job log at Tue Nov 26 13:51:44 EST 2013 ============================================= ============================================= Begin job log summary ... ============================================= There were 2 jobs. JobID: 12345 had an ERROR. We need to use "terminators" /^Begin job log summary/, such that this summary ERROR does not get parsed into JobID: 12346