Getting Data In

What will be LINE_BREAKER for these events?

muizash
Path Finder

2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -

Please write the LINE_BREAKER for these events, i know splunk will automatically do it for these events but these are not the only events I have. I cannot share share those events here. However every time stamp starts like this. If there is additional info to be written in props.conf. Please write

Thanks

0 Karma

arjunpkishore5
Motivator

You don't need line breaker if every line is starting with the timestamp. You just need to break the events before the timestamp.

[your stanza]
TIME_FORMAT = %Y-%m-%d %H:%M:%S,%3N
BREAK_ONLY_BEFORE_DATE = true
SHOULD_LINEMERGE = false

hope this helps.

0 Karma

arjunpkishore5
Motivator

Hi @muizash

Did any of the suggested solutions work for you?

0 Karma

woodcock
Esteemed Legend

Like this:

LINE_BREAKER = ([\r\n]+)\d{4}\-\d{2}\-\d{2} \d{2}:\d{2}:\d{2},\d{3}
SHOULD_LINEMERGE = false
0 Karma

wmyersas
Builder

Your linebreaker should look like this in your props.conf:

[your:sourcetype]
LINE_BREAKER = ([\r\n\f]+)
SHOULD_LINEMERGE = false 
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S,%3N
MAX_TIMESTAMP_LOOKAHEAD = 30

It's always a best practice to formally set both the LINE_BREAKER and SHOULD_LINEMERGE (according to the props.conf spec, you must set SHOULD_LINEMERGE when you set LINE_BREAKER).

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @muizash,
did you already tried something like this in your props.conf?

[your_sourcetype]
SHOULD_LINEMERGE = false
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S,%3N

Ciao.
Giuseppe

0 Karma

muizash
Path Finder

yes, thanks

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...