Getting Data In

How to break events at the hex message delimiter?

ankithreddy777
Contributor

I have to break events based on the hex message delimiter. When I ingest data into Splunk, it is showing as letter 'x' or whitespace between events. How do I break events at the hex message delimiter?

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi ankithreddy777,

I think you can try the following in props.conf:

FIELD_DELIMITER =
* Tells Splunk which character delimits or separates fields in the specified file or source.
* This attribute supports the use of special characters.

Hope it helps. Thanks!
Hunter

0 Karma

lukejadamec
Super Champion

Probably 'REPORT' in props.conf and 'DELIMS' in transforms.conf.
More information would be nice.

0 Karma

somesoni2
Revered Legend

Sample entries please..

Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...