<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to parse jenkins logs? in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656805#M2499</link>
    <description>&lt;DIV&gt;Hello&lt;/DIV&gt;&lt;DIV&gt;Thanks for your reply&lt;/DIV&gt;&lt;DIV&gt;I cannot attach the real logs but let have an example&lt;/DIV&gt;&lt;DIV&gt;The log will start with timestamp so&lt;/DIV&gt;&lt;DIV&gt;08:30:23 Started by Sarit Shvartzman&lt;/DIV&gt;&lt;DIV&gt;Raw&lt;/DIV&gt;&lt;DIV&gt;Raw&lt;/DIV&gt;&lt;DIV&gt;Raw&lt;/DIV&gt;&lt;DIV&gt;08:32:34 Finished:&lt;/DIV&gt;&lt;DIV&gt;I want all of this to be in one event&lt;/DIV&gt;&lt;DIV&gt;Instead of as it now that it breaks by raw&lt;/DIV&gt;</description>
    <pubDate>Wed, 06 Sep 2023 10:55:57 GMT</pubDate>
    <dc:creator>sarit_s6</dc:creator>
    <dc:date>2023-09-06T10:55:57Z</dc:date>
    <item>
      <title>How to parse jenkins logs?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656658#M2493</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I'm using Splunk cloud, i have jenkins logs indexed to my system but for some reason breaks&lt;/P&gt;
&lt;P&gt;I took an output example and add it to Splunk with the "Add Data" option and there it looks ok but when im searching for the sourcetype it is still broken.&lt;/P&gt;
&lt;P&gt;What is the best way to parse jenkins logs ?&lt;/P&gt;
&lt;P&gt;this is my sourcetype configuration :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[ console_logs ]
CHARSET=UTF-8
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=true
category=Structured
disabled=false
pulldown_type=true&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and i want it to be shown with the bulks :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;time&amp;gt; Started by user
&amp;lt;time&amp;gt; Finished:&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 19:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656658#M2493</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2023-09-05T19:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse jenkins logs?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656759#M2498</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260281"&gt;@sarit_s6&lt;/a&gt;&amp;nbsp;- Kindly provide sample raw data and tell how you would like to see the events being broken, so we can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 05:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656759#M2498</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-09-06T05:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse jenkins logs?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656805#M2499</link>
      <description>&lt;DIV&gt;Hello&lt;/DIV&gt;&lt;DIV&gt;Thanks for your reply&lt;/DIV&gt;&lt;DIV&gt;I cannot attach the real logs but let have an example&lt;/DIV&gt;&lt;DIV&gt;The log will start with timestamp so&lt;/DIV&gt;&lt;DIV&gt;08:30:23 Started by Sarit Shvartzman&lt;/DIV&gt;&lt;DIV&gt;Raw&lt;/DIV&gt;&lt;DIV&gt;Raw&lt;/DIV&gt;&lt;DIV&gt;Raw&lt;/DIV&gt;&lt;DIV&gt;08:32:34 Finished:&lt;/DIV&gt;&lt;DIV&gt;I want all of this to be in one event&lt;/DIV&gt;&lt;DIV&gt;Instead of as it now that it breaks by raw&lt;/DIV&gt;</description>
      <pubDate>Wed, 06 Sep 2023 10:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-parse-jenkins-logs/m-p/656805#M2499</guid>
      <dc:creator>sarit_s6</dc:creator>
      <dc:date>2023-09-06T10:55:57Z</dc:date>
    </item>
  </channel>
</rss>

