<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Line breaking using props.conf in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688677#M19454</link>
    <description>&lt;P&gt;Ugh. That's bad. While &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; 's solution should work (you can try to be even more explicit with more precise definition of the timestamp format for linebreaking you'll be getting some ugly trailers to some of your events. Also since these are contents of a json field, some characters will most probably be escaped.&lt;/P&gt;&lt;P&gt;It would be best if you managed to:&lt;/P&gt;&lt;P&gt;1) Work with the source side so that you get your event in a more reasonable way (without all this json overhead) - preferred option&lt;/P&gt;&lt;P&gt;2) If you can't do that, use a pre-processing step in form of an external script/tool/whatever which will "unpack" those jsons and just leave you with raw data.&lt;/P&gt;</description>
    <pubDate>Sat, 25 May 2024 16:09:03 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-05-25T16:09:03Z</dc:date>
    <item>
      <title>Line breaking using props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688575#M19447</link>
      <description>&lt;P&gt;{"body":"&lt;FONT color="#FF0000"&gt;2024-04-29T20:25:08.175779&lt;/FONT&gt; HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XX Logon Failed: Anonymous\n&lt;FONT color="#FF0000"&gt;2024-04-29T20:25:10.190339&lt;/FONT&gt; HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n&lt;FONT color="#FF0000"&gt;2024-04-29T20:25:10.241220&lt;/FONT&gt; HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n2024-04-29T20:25:10.342343 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n","x-opt-sequence-number-epoch":-1,"x-opt-sequence-number":1599,"x-opt-offset":"3642132344","x-opt-enqueued-time":1714422318556}&lt;BR /&gt;{"body":"&lt;FONT color="#FF0000"&gt;2024-04-24T12:46:29.292880&lt;/FONT&gt; HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n&lt;FONT color="#FF0000"&gt;2024-04-24T12:46:34.634829&lt;/FONT&gt; HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Failed: Anonymous\n2024-04-24T12:46:34.651499 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n2024-04-24T12:46:34.653643 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Failed: Anonymous\n2024-04-24T12:46:34.662636 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n2024-04-24T12:46:34.712475 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n2024-04-24T12:46:34.723543 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n2024-04-24T12:46:36.403615 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Failed: Anonymous\n","x-opt-sequence-number-epoch":-1,"x-opt-sequence-number":156626,"x-opt-offset":"3560527888816","x-opt-enqueued-time":1713962799368}&lt;BR /&gt;{"body":"2024-04-24T01:04:30.375693 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Failed: Anonymous\n2024-04-24T01:04:35.034067 HTTPS REST-API 10.10.11.11:2132 XXX-XXX-XXX Logon Success: blah-blah-blah\n","x-opt-sequence-number-epoch":-1,"x-opt-sequence-number":156,"x-opt-offset":"355193796","x-opt-enqueued-time":171392067}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have pasted my raw log samples in the above space. Can someone please help me to break these into multiple evnts using props.conf&lt;/P&gt;&lt;P&gt;I wish to break the lines before each timestamp (highlighted).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ranjitha&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 07:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688575#M19447</guid>
      <dc:creator>RanjithaN99</dc:creator>
      <dc:date>2024-05-24T07:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking using props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688605#M19450</link>
      <description>&lt;P&gt;Try&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = ()\d{4}-\d\d&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 24 May 2024 14:06:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688605#M19450</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-05-24T14:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking using props.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688677#M19454</link>
      <description>&lt;P&gt;Ugh. That's bad. While &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; 's solution should work (you can try to be even more explicit with more precise definition of the timestamp format for linebreaking you'll be getting some ugly trailers to some of your events. Also since these are contents of a json field, some characters will most probably be escaped.&lt;/P&gt;&lt;P&gt;It would be best if you managed to:&lt;/P&gt;&lt;P&gt;1) Work with the source side so that you get your event in a more reasonable way (without all this json overhead) - preferred option&lt;/P&gt;&lt;P&gt;2) If you can't do that, use a pre-processing step in form of an external script/tool/whatever which will "unpack" those jsons and just leave you with raw data.&lt;/P&gt;</description>
      <pubDate>Sat, 25 May 2024 16:09:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Line-breaking-using-props-conf/m-p/688677#M19454</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-05-25T16:09:03Z</dc:date>
    </item>
  </channel>
</rss>

