Getting Data In

How to configure proper line breaking for indexing ftp log files?

shane_berry
Engager

I have some ftp log files that I am indexing and when I search, there will be events that have 275 lines in them instead of one line which is what I want. The lines look like this:

19:00 | 00:00:28.387 | 75   -Sent-> 1004 SSH_FXP_READDIR /Outbound/SON/.
19:00 | 00:00:28.434 | 75   <-Recv- 1004 SSH_FXP_STATUS EOF(1)
19:00 | 00:00:28.434 | 75   -Sent-> 1005 SSH_FXP_CLOSE 
19:00 | 00:00:28.496 | 75   <-Recv- 1005 SSH_FXP_STATUS OK

They have a carriage return and line feed at the end of each line. I have tried the following settings in props.conf with no luck:

SHOULD_LINEMERGE = false
LINE_BREAKER=[\r\n]+ (both escaped)
TIME_PREFIX = |\s (both escaped)
TIME_FORMAT = %H:%M:%S.%3N

Any ideas?

0 Karma
1 Solution

shane_berry
Engager

This is working now with these settings.

View solution in original post

0 Karma

shane_berry
Engager

This is working now with these settings.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...