<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: props.conf not working  to break  the events after pipe line in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480232#M9403</link>
    <description>&lt;P&gt;Hi @ashwinipatil007 &lt;/P&gt;

&lt;P&gt;Try the following in your props.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\|)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It wont hurt putting this on your UF, but it wont do anything. This needs to be on your indexers, or (heavy forwarders if you use them)&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2020 15:23:29 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2020-02-28T15:23:29Z</dc:date>
    <item>
      <title>props.conf not working  to break  the events after pipe line</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480230#M9401</link>
      <description>&lt;P&gt;i am trying to break the events in the below data after each pipe (|),placed the props.conf on both UF and HF still doesn't apply&lt;BR /&gt;
but when I am trying the same props.conf in the  UI (add data) before indexing the data it is working.&lt;/P&gt;

&lt;P&gt;HOSTNAME=**&lt;STRONG&gt;&lt;EM&gt;,PROGRAM=MANAGER,FILENAME=TEST,STATUS=UP|HOSTNAME=&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;,PROGRAM=EXTRACT,FILENAME=TEST,STATUS=UP|HOSTNAM&lt;BR /&gt;
E=&lt;/STRONG&gt;&lt;STRONG&gt;&lt;EM&gt;,PROGRAM=EXTRACT,FILENAME=TEST,STATUS=UP|HOSTNAME=&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;,PROGRAM=EXTRACT,FILENAME=TEST,STATUS=UP|HOSTNAME=&lt;/STRONG&gt;*&lt;BR /&gt;
&lt;STRONG&gt;,PROGRAM=EXTRACT,FILENAME=TEST,STATUS=UP|HOSTNAME=&lt;/STRONG&gt;***,PROGRAM=EXTRACT,FILENAME=TEST,STATUS=UP&lt;/P&gt;

&lt;P&gt;tried with below 2 props.conf.&lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
EVENT_BREAKER_ENABLE=true&lt;BR /&gt;
EVENT_BREAKER=(|)&lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
BREAK_ONLY_BEFORE = (|)&lt;/P&gt;

&lt;P&gt;I am using splunk 7.0 version&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480230#M9401</guid>
      <dc:creator>ashwinipatil007</dc:creator>
      <dc:date>2020-09-30T04:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf not working  to break  the events after pipe line</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480231#M9402</link>
      <description>&lt;P&gt;Do you not have timestamps in any of your events?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 15:17:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480231#M9402</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-28T15:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf not working  to break  the events after pipe line</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480232#M9403</link>
      <description>&lt;P&gt;Hi @ashwinipatil007 &lt;/P&gt;

&lt;P&gt;Try the following in your props.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\|)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It wont hurt putting this on your UF, but it wont do anything. This needs to be on your indexers, or (heavy forwarders if you use them)&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 15:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480232#M9403</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-28T15:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf not working  to break  the events after pipe line</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480233#M9404</link>
      <description>&lt;P&gt;nope.&lt;BR /&gt;
the props.conf are working fine when I try it before indexing the data but when I place them on HF (tried on UF as well) it is not breaking the events as expected.tried with below props.conf as well but no luck&lt;BR /&gt;
I need to break the events before the PIPE in the above content.&lt;BR /&gt;
any idea?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 08:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-not-working-to-break-the-events-after-pipe-line/m-p/480233#M9404</guid>
      <dc:creator>ashwinipatil007</dc:creator>
      <dc:date>2020-03-03T08:26:40Z</dc:date>
    </item>
  </channel>
</rss>

