I have a script generating an output, however all my output is being registered as one event. I am trying to break each line into an. I tried using the line breaker with regex for end of line. But that fails.
Example of the output.
Status Tag DisplayName
------ ---- -----------
Quit jflower James
Terminated wpunch William
Quit madams Mark
Terminated jtota Jeff
Quit wbaker Baker
Quit sjohson Shawn
I am trying to extract the header and
It was not breaking properly because of how powershell formats it output. I converted the output to csv and then ingested it into splunk. It worked like a charm
You need the multikv
command:
http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Multikv
What sourcetype did you specify for this input?
The default LINE_BREAKER setting is [\r\n]
which should break events after EOL.
Please share your props.conf settings.
Your posting was cut off. What are you trying to extract with the header?