Getting Data In

How to break my events?

chintan_shah
Path Finder

Hi,
i am trying to break the event which we receive from our hand held devices into separate events but its not working properly.
The logs doesn't have any LINE BREAKER and i am using /msg> as delimiter but its not working.
Can some one help me in breaking this event?

Sample Logs:

0 Karma
1 Solution

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19
0 Karma

chintan_shah
Path Finder

Thanks @somesoni2.
It worked but the end of the event is looking as < instead of

PDT Socket Created642949672951<

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/03/30 09:41:05'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>6</v></z><z><v n='Socket Handle'>4294967295</v></z><z><v n='(logs removed)'>1</v></z></b><
0 Karma

somesoni2
Revered Legend

It's actually removing string in first brackets in LINE_BREAKER. If you need that you can use below,

[yoursourcetype]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=(\<msg)
 TIME_PREFIX=d='
 TIME_FORMAT=%Y/%m/%d %H:%M:%S
 MAX_TIMESTAMP_LOOKAHEAD=19
 SEDCMD-addheader = s/^(.+)/<msg \1/
0 Karma

chintan_shah
Path Finder

Thanks Somesoni2. It worked.

0 Karma

somesoni2
Revered Legend

You're missing sample logs here.

0 Karma

chintan_shah
Path Finder

Hi
Please find the sample log
PDT Socket Created2214294967295Extracted PDT Request

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>221</v></z><z><v n='Socket Handle'>4294967295</v></z></b></msg><msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='FetchRequest()'/><i>Extracted PDT Request</i></msg>
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...