Getting Data In

How to break events at the hex message delimiter?

ankithreddy777
Contributor

I have to break events based on the hex message delimiter. When I ingest data into Splunk, it is showing as letter 'x' or whitespace between events. How do I break events at the hex message delimiter?

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi ankithreddy777,

I think you can try the following in props.conf:

FIELD_DELIMITER =
* Tells Splunk which character delimits or separates fields in the specified file or source.
* This attribute supports the use of special characters.

Hope it helps. Thanks!
Hunter

0 Karma

lukejadamec
Super Champion

Probably 'REPORT' in props.conf and 'DELIMS' in transforms.conf.
More information would be nice.

0 Karma

somesoni2
Revered Legend

Sample entries please..

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...