I am looking to find a character (regular expression) in Splunk that searches for and returns values (from a file) starting with a word (ex.Total) and ending with a new empty line (representing a new paragraph etc..).
An random text chosen from the web:
A Memorandum of Understanding was signed by Total and MOGE on July 9, 1992. In addition to the construction of offshore gas facilities by the partners, a separate company in which PTT-EP, MOGE, and other affiliates of Total and Unocal are investors (the Moattama Gas Transportation Company - MGTC) built a 346-kilometer subsea pipeline to bring the gas to landfall in Myanmar, and a 63-kilometer onshore pipeline, with control and metering units, to carry the gas to the border with Thailand, which purchases most of the field's output under a long-term sales and purchase agreement.
Construction was carried out between fall 1995 and mid-1998, with gas production beginning in July 1998. The total investment outlay was approximately US$1 billion. Further capital expenditure will be requiredduring the field's lifetime to drill additional wells and install compressors. The export production threshold of 525 million cubic feet per day was reached in early 2001.
In this case, the regular expression would return the following:
"Total and MOGE on July 9, 1992. In addition to the construction of offshore gas facilities by the partners, a separate company in which PTT-EP, MOGE, and other affiliates of Total and Unocal are investors (the Moattama Gas Transportation Company - MGTC) built a 346-kilometer subsea pipeline to bring the gas to landfall in Myanmar, and a 63-kilometer onshore pipeline, with control and metering units, to carry the gas to the border with Thailand, which purchases most of the field's output under a long-term sales and purchase agreement"
To make it easier my text doesn't contain 7 consecutive empty spaces, you can look for a new line that contain 7 consecutive spaces at the beginning.