Hi
I am just exploring how can event break settings be used.Need some help with it.
My input data is simply a text document, containing just a paragraph.
I want Splunk to take every word as one event.
What LINE_BREAKER do I specify in props.conf??
Can it be done in any other way?
To get each word split into its own event you could do this:
LINE_BREAKER=(\W+)
SHOULD_LINEMERGE=0
That will break events at every group of non-word characters and consume them so they will not appear in your event.
To get each word split into its own event you could do this:
LINE_BREAKER=(\W+)
SHOULD_LINEMERGE=0
That will break events at every group of non-word characters and consume them so they will not appear in your event.
It worked! Thanks a million 🙂