<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you help me extract multiple lines per event? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407385#M7024</link>
    <description>&lt;P&gt;That would help but I do not have access to the .conf. I actually have to generate a SED syntax, but when I do that it bricks my search. This was a search I generated a year ago and I am unable to remember how I set this up. That's why I am trying to get assistance in rebuilding it, since I am being asked to generate a different result export to include the STAP, Last Response, db IP, dbhost, type, total time down(new request).  &lt;/P&gt;</description>
    <pubDate>Tue, 04 Dec 2018 15:45:35 GMT</pubDate>
    <dc:creator>reneedeleon</dc:creator>
    <dc:date>2018-12-04T15:45:35Z</dc:date>
    <item>
      <title>Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407378#M7017</link>
      <description>&lt;P&gt;I have multiple lines to extract and break down into separate fields, I have a search I've been using, but I am running into issues trying to extract multiple fields.&lt;/P&gt;

&lt;P&gt;The Data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;30&amp;gt;2018-11-29T15:59:59.128110+00:00 myserver.iskindof.broken.com 111.222.333.444 ["Nov 29 10:59:59" myserver] the_log[5930]: #012#012Alert Name: Inactive nic Since. Alert Description: nics Inactive for a given period of time.#012Current value: 3.0 #012Base query value: 0.0 #012Threshold: 0.0 #012Query period: 11/29/18 - 11/29/18 #012Alert Classification:  #012Category:  #012Severity: INFO#012#012Recommended Action:#012#012 #012#012Alert Details#012S-TAP Host    DB Server Type Status   Last Response       Primary Host Name KTAP Installed TEE Installed Shared Memory Driver Installed DB2 Shared Memory Driver Installed LHMON Driver Installed Named Pipes Driver Installed Hunter DBS App Server Installed Count
#012111.111.111.110      ORACLE         Inactive 2018-08-29 12:46:00 111.111.111.200   Yes  No      No  No  Yes No          No                   1     
#012111.111.111.110:FAM                 Inactive 2018-10-27 03:25:00 111.111.111.200   No       No      No      No      Yes     No              No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     No      NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-10-11 19:09:46 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-10-11 17:31:04 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      No      Yes                     No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No      NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No              NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No              NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No              NULL    No                   1     
#012111.111.111.110:FAM                 Inactive 2018-10-20 09:18:01 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110:FAM                 Inactive 2018-11-28 01:39:26 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:13 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110:FAM                 Inactive 2018-08-23 15:16:36 111.111.111.200   Yes      No      No      No      Yes     No                      No                   1     
#012111.111.111.110:FAM                 Inactive 2018-08-23 15:16:41 111.111.111.200   Yes      No      No      No      Yes     No                      No                   1     
#012111.111.111.110:FAM                 Inactive 2018-10-20 09:23:01 111.111.111.200   No       No  No      No      Yes     No                      No                   1    
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The Search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=database* Inactive 
| rex field=_raw "^[^ \n]* (?P[^ ]+)"
| rex field=_raw "^(?:[^ \n]* ){2}(?P[^ ]+)"
| rex field=_raw "(?\s)"
| rex field=_raw "[#]\d{3}(?\d\s+\w{8}\s\d+\S\d+\S\d+\s\d+\S\d+\S\d+(\S\d)?\s+(\d+\S\d+\S\d+\S\d+)?)" max_match=0
| rex field=_raw "[#]\d{3}(?\w+\S\w{13}\S\w{3}\s+\w{8}\s\d+\S\d+\S\d+\s\d+\S\d+\S\d+(\S\d)?\s+(\d+\S\d+\S\d+\S\d+)?)" max_match=0
| rex field=_raw "[#]\d{3}(?\d+\S\d+\S\d+\S\d+\S*\w*\s+\w*\s*\w{8}\s\d+\S\d+\S\d+\s\d+\S\d+\S\d+(\S\d)?\s+(\d+\S\d+\S\d+\S\d+)?)" max_match=0
| mvexpand Alert
| rex field=Alert "(?P\d)\s+(?\w{8}\s(?\d+)\S(?\d+)\S(?\d+)\s(?\d+)\S(?\d+)\S(?\d+)(\S\d)?)\s+(?\d+\S\d+\S\d+\S\d+)?"
| rex field=Alert "(?P\w+\S\w{13}\S\w{3})\s+(?\w{8}\s(?\d+)\S(?\d+)\S(?\d+)\s(?\d+)\S(?\d+)\S(?\d+)(\S\d)?)\s+(?\d+\S\d+\S\d+\S\d+)?"
| rex field=Alert "(?P\d+\S\d+\S\d+\S\d+)\S*\w*\s+\w*\s*(?\w{8}\s(?\d+)\S(?\d+)\S(?\d+)\s(?\d+)\S(?\d+)\S(?\d+)(\S\d)?)\s+(?\d+\S\d+\S\d+\S\d+)?"
| eval nic=case(isnull(nic),"Nothing",1=1,nic)
| eval db=case(isnull(db),"Nothing",1=1,db)
| lookup dnslookup clientip as db OUTPUT clienthost as Host
| eval Hostname=case(isnull(Host),"Unknown",1=1,Host)
| table server, ip, db,  type,  Host,  date_down,  nic
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What I am trying to get, but separated into individual lines:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;server                            IP                       db                               type                Inactive date                                nic 
1brokenserver.com     100.00.000.1        111.111.111.110:FAM   oracle or NULL  Inactive 2018-10-20 09:23:01    111.111.111.200
2brokenserver.com     100.00.000.1        111.111.111.110       oracle or NULL  Inactive 2018-10-20 09:23:01    111.111.111.200
abrokenserver.com     100.00.000.1        111.111.111.110:FAM   oracle or NULL  Inactive 2018-10-20 09:23:01    111.111.111.200
etc..etc..
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is  there something I am missing or is there a book for idiots that could assist me or does someone have advice?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 16:44:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407378#M7017</guid>
      <dc:creator>reneedeleon</dc:creator>
      <dc:date>2018-11-29T16:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407379#M7018</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;Your data looks kind of mixed (first line in comparison to the rest).&lt;/P&gt;

&lt;P&gt;How much information do you need from line #1?&lt;/P&gt;

&lt;P&gt;The Events, starting from line #2 look structured enough to let splunk auto-extract fields. On top of those events, some spl should yield into the desired result.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 11:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407379#M7018</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2018-12-03T11:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407380#M7019</link>
      <description>&lt;P&gt;None of line one is needed. However the auto extract does not allow me to me pull the multiple fields and individualize the data I want to extract. Also the rex generator will not allow me to extract what is needed. I keep getting "The extraction failed. If you are extracting multiple fields, try removing one or more fields. Start with extractions that are embedded within longer text strings." message. But I don't have any extractions in the first place. Please advise.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 22:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407380#M7019</guid>
      <dc:creator>reneedeleon</dc:creator>
      <dc:date>2018-12-03T22:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407381#M7020</link>
      <description>&lt;P&gt;Okay ... as for me, there are two approaches:&lt;BR /&gt;
(A): dynamically use the header within your first line (I think it is the text after the last occurance of &lt;CODE&gt;#012&lt;/CODE&gt;) at index time (not detailled here)&lt;/P&gt;

&lt;P&gt;(B): Use &lt;CODE&gt;rex&lt;/CODE&gt; on &lt;CODE&gt;_raw&lt;/CODE&gt; in a slightly different way. I used &lt;CODE&gt;\S&lt;/CODE&gt; (capitalized) to match everything but white spaces and &lt;CODE&gt;\s&lt;/CODE&gt; (lower case) to match white space. There is one odd field (third to the end) that sometimes is filled with NULL, sometimes not at all. Moreover the "DB Server Type" is not always present.&lt;/P&gt;

&lt;P&gt;I used your raw data from above where I had a leading space in each line. I think that is due to copying it from here. That is the reason for me starting the regex with &lt;CODE&gt;^\s{0,1}...&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Using this spl/regex I have the data in fields to start working with:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="main" sourcetype="..."
| rex field=_raw "^\s{0,1}(?&amp;lt;field_01&amp;gt;#\d{3})(?&amp;lt;field_02&amp;gt;\S+)\s{6}(?&amp;lt;field_03&amp;gt;\S+)?\s+(?&amp;lt;field_04&amp;gt;\S+)\s+(?&amp;lt;field_05&amp;gt;\S+)\s+(?&amp;lt;field_06&amp;gt;\S+)\s+(?&amp;lt;field_07&amp;gt;\S+)\s+(?&amp;lt;field_08&amp;gt;\S+)\s+(?&amp;lt;field_09&amp;gt;\S+)\s+(?&amp;lt;field_10&amp;gt;\S+)\s+(?&amp;lt;field_11&amp;gt;\S+)\s+(?&amp;lt;field_12&amp;gt;\S+)\s+(?&amp;lt;field_13&amp;gt;\S+)\s+(?&amp;lt;field_14&amp;gt;NULL\s+)?(?&amp;lt;field_15&amp;gt;\S+)\s+(?&amp;lt;field_16&amp;gt;\S+)\s+$"
| eval "Last Response" = field_05." ".field_06
| rename
    field_01 as "PREFIX"
    field_02 as "S-TAP Host"
    field_03 as "DB Server Type"
    field_04 as "Status"
    field_07 as "Primary Host Name"
    field_08 as "KTAP Installed"
    field_09 as "TEE Installed"
    field_10 as "Shared Memory Driver Installed"
    field_11 as "DB2 Shared Memory Driver Installed"
    field_12 as "LHMON Driver Installed"
    field_13 as "Named Pipes Driver Installed"
    field_14 as "UNKNOWN"
    field_15 as "Hunter DBS App Server Installed"
    field_16 as "Count"    
| table "PREFIX" "S-TAP Host" "DB Server Type" "Status" "Last Response" "Primary Host Name" "KTAP Installed" "TEE Installed" "Shared Memory Driver Installed" "DB2 Shared Memory Driver Installed" "LHMON Driver Installed" "Named Pipes Driver Installed" "UNKNOWN" "Hunter DBS App Server Installed" "Count"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Dec 2018 11:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407381#M7020</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2018-12-04T11:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407382#M7021</link>
      <description>&lt;P&gt;I tried this and it worked but it displayed nothing in the lines but the columns were relabeled. Could it be I need to have a fillnull for each column? Or would I need to plugin the original query as well or make another rex for each item I am trying to extract?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 14:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407382#M7021</guid>
      <dc:creator>reneedeleon</dc:creator>
      <dc:date>2018-12-04T14:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407383#M7022</link>
      <description>&lt;P&gt;Two tips:&lt;BR /&gt;
- looks like this data is being passed through rsyslog? You might want to configure rsyslog with &lt;CODE&gt;escapecontrolcharactersonreceive off&lt;/CODE&gt; such that those #012 are just printed as the newlines they are meant to be. If you don't have control over the syslog daemon, then I guess &lt;CODE&gt;SEDCMD-fixnewlines = s/#012/\n/g&lt;/CODE&gt; (in props.conf) should also do the trick.&lt;/P&gt;

&lt;P&gt;This should make your data look like this in Splunk:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;30&amp;gt;2018-11-29T15:59:59.128110+00:00 myserver.iskindof.broken.com 111.222.333.444 ["Nov 29 10:59:59" myserver] the_log[5930]: 
Alert Name: Inactive nic Since. Alert Description: nics Inactive for a given period of time.
Current value: 3.0 
Base query value: 0.0 
Threshold: 0.0 
Query period: 11/29/18 - 11/29/18 
Alert Classification:  
Category:  
Severity: INFO
Recommended Action:
Alert Details
S-TAP Host    DB Server Type Status   Last Response       Primary Host Name KTAP Installed TEE Installed Shared Memory Driver Installed DB2 Shared Memory Driver Installed LHMON Driver Installed Named Pipes Driver Installed Hunter DBS App Server Installed Count
111.111.111.110      ORACLE         Inactive 2018-08-29 12:46:00 111.111.111.200   Yes    No      No    No    Yes    No            No                   1     
111.111.111.110:FAM                 Inactive 2018-10-27 03:25:00 111.111.111.200   No       No      No      No      Yes     No                No                   1     
111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     No        NULL    No                   1     
111.111.111.110      ORACLE         Inactive 2018-10-11 19:09:46 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;UL&gt;
&lt;LI&gt;have a look at the multikv command: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multikv"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multikv&lt;/A&gt; which is specifically designed to handle this type of tabular data inside events. When you have applied above fix for the #012's, you would want to do &lt;CODE&gt;| multikv forceheader=12&lt;/CODE&gt; (to use line 12 as the header line). If you make sure you extract all the header fields from above the table before you perform the multikv command, those general fields will be copied over to all the undividually split events generated by multikv.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407383#M7022</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-12-04T15:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407384#M7023</link>
      <description>&lt;P&gt;While trying that with your sample data, it seems the multikv command doesn't work very nicely with the column names that contain a space. So you might need to do a little SED preprocessing to fix that.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407384#M7023</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-12-04T15:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407385#M7024</link>
      <description>&lt;P&gt;That would help but I do not have access to the .conf. I actually have to generate a SED syntax, but when I do that it bricks my search. This was a search I generated a year ago and I am unable to remember how I set this up. That's why I am trying to get assistance in rebuilding it, since I am being asked to generate a different result export to include the STAP, Last Response, db IP, dbhost, type, total time down(new request).  &lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407385#M7024</guid>
      <dc:creator>reneedeleon</dc:creator>
      <dc:date>2018-12-04T15:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407386#M7025</link>
      <description>&lt;P&gt;&lt;CODE&gt;| rex mode=sed " s/#012/\n/g"&lt;/CODE&gt;&lt;BR /&gt;
That should fix the #012 junk.&lt;/P&gt;

&lt;P&gt;Then see what your data looks like and try applying &lt;CODE&gt;| multikv&lt;/CODE&gt;. I'm getting some mixed results testing it with your sample data, but that might be because of how this has been copy pasted from your system to this discussion, to my system.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 16:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407386#M7025</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-12-04T16:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407387#M7026</link>
      <description>&lt;P&gt;Most probably your the values are tab separated. I assumed spaces. You could verify this in an good text editor or by using &lt;CODE&gt;cat&lt;/CODE&gt;:&lt;BR /&gt;
&lt;CODE&gt;cat -T yourfile.txt&lt;/CODE&gt; ... tabs will be displayed as &lt;CODE&gt;^I&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 16:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407387#M7026</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2018-12-04T16:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407388#M7027</link>
      <description>&lt;P&gt;Yes, Lines 1 through 31 are all as one event. That's why I am trying to extract each part of the event line by line.  &lt;/P&gt;

&lt;P&gt;Device  Device IP   Inactive Date    db IP  db Host     TAP         total time down&lt;BR /&gt;
server1   0.0.0.0            aug 1 1900     0.0.0.0   dbserver    0.0.0.0         7 days&lt;BR /&gt;
''         ''    ''        ''            ''                ''     ''         ''    ''           ''     ''       ''           2 weeks&lt;BR /&gt;
''         ''    ''        ''            ''                ''     ''         ''    ''           ''     ''       ''           1 month&lt;BR /&gt;
''         ''    ''        ''            ''                ''     ''         ''    ''           ''     ''       ''           4 hours&lt;/P&gt;

&lt;P&gt;etc etc&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 20:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407388#M7027</guid>
      <dc:creator>reneedeleon</dc:creator>
      <dc:date>2018-12-04T20:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407389#M7028</link>
      <description>&lt;P&gt;Some are tab others are individualized. But since all of the data is in one event, I am still trying to figure out how to separate the data in each event. &lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 17:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407389#M7028</guid>
      <dc:creator>reneedeleon</dc:creator>
      <dc:date>2018-12-07T17:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me extract multiple lines per event?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407390#M7029</link>
      <description>&lt;P&gt;I think that this will get you most of the way there:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw="&amp;lt;30&amp;gt;2018-11-29T15:59:59.128110+00:00 myserver.iskindof.broken.com 111.222.333.444 [\"Nov 29 10:59:59\" myserver] the_log[5930]: #012#012Alert Name: Inactive nic Since. Alert Description: nics Inactive for a given period of time.#012Current value: 3.0 #012Base query value: 0.0 #012Threshold: 0.0 #012Query period: 11/29/18 - 11/29/18 #012Alert Classification:  #012Category:  #012Severity: INFO#012#012Recommended Action:#012#012 #012#012Alert Details#012S-TAP Host    DB Server Type Status   Last Response       Primary Host Name KTAP Installed TEE Installed Shared Memory Driver Installed DB2 Shared Memory Driver Installed LHMON Driver Installed Named Pipes Driver Installed Hunter DBS App Server Installed Count
#012111.111.111.110      ORACLE         Inactive 2018-08-29 12:46:00 111.111.111.200   Yes    No      No    No    Yes    No            No                   1     
#012111.111.111.110:FAM                 Inactive 2018-10-27 03:25:00 111.111.111.200   No       No      No      No      Yes     No                No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     No        NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-10-11 19:09:46 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-10-11 17:31:04 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:14 111.111.111.200   Yes      No      No      No      No      Yes                     No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No        NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No              NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No              NULL    No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:14 111.111.111.200   No       No      No      No      Yes     No              NULL    No                   1     
#012111.111.111.110:FAM                 Inactive 2018-10-20 09:18:01 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110:FAM                 Inactive 2018-11-28 01:39:26 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      ORACLE         Inactive 2018-08-27 08:59:13 111.111.111.200   No       No      No      No      Yes     No                      No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110      MSSQL          Inactive 2018-08-27 08:59:13 111.111.111.200   Yes      No      No      No      Yes     Yes                     No                   1     
#012111.111.111.110:FAM                 Inactive 2018-08-23 15:16:36 111.111.111.200   Yes      No      No      No      Yes     No                      No                   1     
#012111.111.111.110:FAM                 Inactive 2018-08-23 15:16:41 111.111.111.200   Yes      No      No      No      Yes     No                      No                   1     
#012111.111.111.110:FAM                 Inactive 2018-10-20 09:23:01 111.111.111.200   No       No    No      No      Yes     No                      No                   1    " 

| rename COMMENT AS "Everything above generates sample event data; everything below is your solution"

| rex max_match=0 "[\r\n]+\#\d{3}(?&amp;lt;raw&amp;gt;[^\r\n]+)"
| rename host AS server
| table server raw
| mvexpand raw
| rename raw AS _raw
| rex max_match=0 "(?&amp;lt;nic&amp;gt;\S+)\s+(?:(?&amp;lt;db&amp;gt;\S+)\s+)?(?&amp;lt;type&amp;gt;\S+)\s+(?&amp;lt;date&amp;gt;\d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2})\s+(?&amp;lt;IP&amp;gt;\S+)\s+(?&amp;lt;bools&amp;gt;(Yes|No).*?)\s*$"
| fields - _raw
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 03 Feb 2019 00:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Can-you-help-me-extract-multiple-lines-per-event/m-p/407390#M7029</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-03T00:12:05Z</dc:date>
    </item>
  </channel>
</rss>

