Hi everyone,
Can someone please explain why these steps won't work? XML file that I input in Splunk are one event, like this:
inputs.conf
[monitor://c:/to_the_file]
Sourcetype = aaa
props.conf
[aaa]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]*)
I have tried this from Splunk Web (upload file and configured SHOULD_LINEMERGE = false
and
LINE_BREAKER = ([\r\n]*)
) and it worked, but when I do it from .conf files, it won't. Any ideas?
And of course, how can I configure date and time to be recognized from Splunk?
Thanks
Give this a try
props.conf
[aaa]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]*)(?=\<LOG\>)
TIME_PREFIX = DATE\>
TIME_FORMAT = %Y%m%d</DATE><TIME>%H%M%S
MAX_TIMESTAMP_LOOKAHEAD = 27
Give this a try
props.conf
[aaa]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]*)(?=\<LOG\>)
TIME_PREFIX = DATE\>
TIME_FORMAT = %Y%m%d</DATE><TIME>%H%M%S
MAX_TIMESTAMP_LOOKAHEAD = 27
Thanks for helping,
ok, we broke logs now with those lines, but the date and time are not recognized from splunk. I have read that I should make datetime.xml file a configure it along with props.conf?
misspell :
LINE_BREAKER = ([\r\n]*)