<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: json file line break in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577354#M10237</link>
    <description>&lt;P&gt;Yes, but I don't see your time format definition. And it's definitely wrong since the time in raw event is different than the event time in splunk.&lt;/P&gt;&lt;P&gt;You could set TIME_PREFIX as well.&lt;/P&gt;</description>
    <pubDate>Sun, 05 Dec 2021 12:21:54 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-12-05T12:21:54Z</dc:date>
    <item>
      <title>json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577350#M10234</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;i have a json log and i cannot figure out how to break the lines correctly&lt;/P&gt;&lt;P&gt;this is how it looks like :&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (1).png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17118i244554C336F3B831/image-size/large?v=v2&amp;amp;px=999" role="button" title="image (1).png" alt="image (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;how can i break the lines that each event will be on is own ?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 10:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577350#M10234</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-12-05T10:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577352#M10235</link>
      <description>&lt;P&gt;Break on date, set proper time format and time prefix?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 11:40:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577352#M10235</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-05T11:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577353#M10236</link>
      <description>&lt;P&gt;yes, you can see it is the image attached&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 11:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577353#M10236</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-12-05T11:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577354#M10237</link>
      <description>&lt;P&gt;Yes, but I don't see your time format definition. And it's definitely wrong since the time in raw event is different than the event time in splunk.&lt;/P&gt;&lt;P&gt;You could set TIME_PREFIX as well.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 12:21:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577354#M10237</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-05T12:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577356#M10238</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sarit_s_0-1638706931992.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17119i37DD81D649788CA9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sarit_s_0-1638706931992.png" alt="sarit_s_0-1638706931992.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;as you can see, it consider 2 events as one for some reason&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 12:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577356#M10238</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-12-05T12:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577357#M10239</link>
      <description>&lt;P&gt;Since you have 4-digit years, would this work better for the break before pattern?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;^\d\d(\d\d\D){6}\S&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 13:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577357#M10239</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-05T13:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577359#M10240</link>
      <description>&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 13:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577359#M10240</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-12-05T13:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: json file line break</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577360#M10241</link>
      <description>&lt;P&gt;I still believe there is something not entirely right with your timestamp recognition. True, in the second screenshot the timestamp "seems" to be right. But.&lt;/P&gt;&lt;P&gt;From the time format you're using, I presume you're somewhere in the US and your local timezone is not GMT. Your event's timestamp is GMT, so...&lt;/P&gt;&lt;P&gt;Anyway, if your logs are reporting time in GMT when they should do in your local time, you have another problem to resolve before you hit some issues with time inconsistency later on.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 14:05:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/json-file-line-break/m-p/577360#M10241</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-05T14:05:13Z</dc:date>
    </item>
  </channel>
</rss>

