I am running the software appliance version of Cisco Prime LMS 4.2.2. I have a syslog Automated Action that sends out an email notification for any severity 0, 1, or 2 messages. Recently I found out that when a Cisco 2960 crashes, it logs 35 messages that form a report, all at severity 1. I want to get 1 email for this and not 35. My first thought is to use a syslog filter to drop most of the messages except for 1. It looks like the definition of a syslog filter has some regular expression capability that would help in this case, but I can't find a description of it anywhere. What is the syntax of the regular expression capability of a syslog filter???