EDIT:
Adding the smartvalues I'm attempting to use:
{{issue.description.match([\s\S]*?(?=Recommendation))}}
{{issue.description.match(^Log\sSource[\s\S]*?(?=\sCount))}}
{{issue.description.match(^Portal.+)}}
EDIT:
It did work for the first one, but the last 2 even like that are pulling empty. I tested the regex again and its capturing in regex testing, but still showing empty. If you could help 1 more time I'd really appreciate it.
for first one:
Log Source Device Name : O365
Source IP : xxx.xxx.xxx.xxx
Source User : someone[.]random@regex[.]com
Alert ID : INSIGHT-81
Alert Date : 2024-01-19 12:39:28
Action : File Downloads
Count : 697
For the second one this is what it is looking for.
Portal - Ticket: 0002334