Getting Data In

What will be LINE_BREAKER for these events?

muizash
Path Finder

2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -
2019-11-06 16:13:21,886 [9] DEBUG B005_01_01BusinessLogic -

Please write the LINE_BREAKER for these events, i know splunk will automatically do it for these events but these are not the only events I have. I cannot share share those events here. However every time stamp starts like this. If there is additional info to be written in props.conf. Please write

Thanks

0 Karma

arjunpkishore5
Motivator

You don't need line breaker if every line is starting with the timestamp. You just need to break the events before the timestamp.

[your stanza]
TIME_FORMAT = %Y-%m-%d %H:%M:%S,%3N
BREAK_ONLY_BEFORE_DATE = true
SHOULD_LINEMERGE = false

hope this helps.

0 Karma

arjunpkishore5
Motivator

Hi @muizash

Did any of the suggested solutions work for you?

0 Karma

woodcock
Esteemed Legend

Like this:

LINE_BREAKER = ([\r\n]+)\d{4}\-\d{2}\-\d{2} \d{2}:\d{2}:\d{2},\d{3}
SHOULD_LINEMERGE = false
0 Karma

wmyersas
Builder

Your linebreaker should look like this in your props.conf:

[your:sourcetype]
LINE_BREAKER = ([\r\n\f]+)
SHOULD_LINEMERGE = false 
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S,%3N
MAX_TIMESTAMP_LOOKAHEAD = 30

It's always a best practice to formally set both the LINE_BREAKER and SHOULD_LINEMERGE (according to the props.conf spec, you must set SHOULD_LINEMERGE when you set LINE_BREAKER).

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @muizash,
did you already tried something like this in your props.conf?

[your_sourcetype]
SHOULD_LINEMERGE = false
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S,%3N

Ciao.
Giuseppe

0 Karma

muizash
Path Finder

yes, thanks

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...