Getting Data In

multiple breaks

akarandjeff
New Member

Is there a way to break by timestamp and by a pattern? Some of my lines have a timestamp and the timestamp filtering works for them, but globs my non-timestamp lines together. Other lines have a common pattern and using BREAK_ONLY_BEFORE works for them, but globs the timestamp lines together. I need to have my cake and eat it too and would like to be able to filter by both.

Tags (1)
0 Karma

hexx
Splunk Employee
Splunk Employee

If your goal is for each line to be indexed as one event, you can simply specify:

SHOULD_LINEMERGE = false

If you want to event-break on time stamps and on another pattern, a simple way to do this is to define BREAK_ONLY_BEFORE with two patterns:

BREAK_ONLY_BEFORE = (pattern1|pattern2)

...where pattern1 matches your time stamps and pattern2 matches the other desired event-breaking string.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...