<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help on custom sourcetype for log parsing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573385#M101424</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;can you try these and check how those are differing?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool props list _json
splunk btool props list ibcapacity&lt;/LI-CODE&gt;&lt;P&gt;Probably there is something which is missing from your new source type?&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Nov 2021 20:47:12 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-11-02T20:47:12Z</dc:date>
    <item>
      <title>help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573382#M101423</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to reach out for some help in creating a custom sourcetype (cloned from _json), I'm calling it "ibcapacity".&amp;nbsp; I've tried to edit the settings under this new sourcetype but my results are even more broken.&lt;/P&gt;&lt;P&gt;The output of the file is formatted correctly in _json (the jq checks come back all good); but when using the _json default sourcetype, the Splunk event gets cut off at 349 lines (the entire file is 392 lines); and the other problem using the standard _json format is that its not fully "color coding" the KVs...but that could be due to the fact that the end brackets aren't in the Splunk event because it was cut off at 349 lines.&lt;/P&gt;&lt;P&gt;So my solution was to try to create a custom sourcetype&amp;nbsp;(cloned from _json), I'm calling it "ibcapacity".&amp;nbsp; I've tried to edit the settings under this new sourcetype but my results are even more broken.&lt;/P&gt;&lt;P&gt;Here is the event when searched in the standard _json sourcetype:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="This is where the Splunk event gets cut off." style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16709iC3E6DBBE01AFE062/image-size/large?v=v2&amp;amp;px=999" role="button" title="LINUX-17194 pic1.png" alt="This is where the Splunk event gets cut off." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;This is where the Splunk event gets cut off.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, the rest of the file has this at the end (past line 349), which doesn't show up in the Splunk event:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;        ],
        "percent_used": 120,
        "role": "Grid Master",
        "total_objects": 529020
    }
]&lt;/LI-CODE&gt;&lt;P&gt;Can this community please help to identify what the correct settings should be for my custom sourcetype, ibcapacity?&amp;nbsp; Why is the Splunk log getting cut off at 349 lines when using sourcetype=_json?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 20:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573382#M101423</guid>
      <dc:creator>freza</dc:creator>
      <dc:date>2021-11-02T20:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573385#M101424</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;can you try these and check how those are differing?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool props list _json
splunk btool props list ibcapacity&lt;/LI-CODE&gt;&lt;P&gt;Probably there is something which is missing from your new source type?&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 20:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573385#M101424</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-02T20:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573389#M101426</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Here is the output for _json:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[_json]
ADD_EXTRA_TIME_FIELDS = True
ANNOTATE_PUNCT = True
AUTO_KV_JSON = true
BREAK_ONLY_BEFORE =
BREAK_ONLY_BEFORE_DATE = True
CHARSET = UTF-8
DATETIME_CONFIG =
DEPTH_LIMIT = 1000
DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = false
HEADER_MODE =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LB_CHUNK_BREAKER_TRUNCATE = 2000000
LEARN_MODEL = true
LEARN_SOURCETYPE = true
LINE_BREAKER = ([\r\n]+)
LINE_BREAKER_LOOKBEHIND = 100
MATCH_LIMIT = 100000
MAX_DAYS_AGO = 2000
MAX_DAYS_HENCE = 2
MAX_DIFF_SECS_AGO = 3600
MAX_DIFF_SECS_HENCE = 604800
MAX_EVENTS = 512
MAX_TIMESTAMP_LOOKAHEAD = 128
MUST_BREAK_AFTER =
MUST_NOT_BREAK_AFTER =
MUST_NOT_BREAK_BEFORE =
NO_BINARY_CHECK = true
SEGMENTATION = indexing
SEGMENTATION-all = full
SEGMENTATION-inner = inner
SEGMENTATION-outer = outer
SEGMENTATION-raw = none
SEGMENTATION-standard = standard
SHOULD_LINEMERGE = True
TRANSFORMS =
TRUNCATE = 10000
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
detect_trailing_nulls = false
disabled = false
maxDist = 100
priority =
pulldown_type = true
sourcetype =
termFrequencyWeightedDist = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And here is the output for ibcapacity:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ibcapacity]
ADD_EXTRA_TIME_FIELDS = True
ANNOTATE_PUNCT = True
AUTO_KV_JSON = true
BREAK_ONLY_BEFORE =
BREAK_ONLY_BEFORE_DATE = true
CHARSET = UTF-8
DATETIME_CONFIG =
DEPTH_LIMIT = 1000
DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = false
HEADER_MODE =
INDEXED_EXTRACTIONS = none
KV_MODE = none
LB_CHUNK_BREAKER_TRUNCATE = 2000000
LEARN_MODEL = true
LEARN_SOURCETYPE = true
LINE_BREAKER = ([\r\n]+)
LINE_BREAKER_LOOKBEHIND = 100
MATCH_LIMIT = 100000
MAX_DAYS_AGO = 2000
MAX_DAYS_HENCE = 2
MAX_DIFF_SECS_AGO = 3600
MAX_DIFF_SECS_HENCE = 604800
MAX_EVENTS = 512
MAX_TIMESTAMP_LOOKAHEAD = 128
MUST_BREAK_AFTER =
MUST_NOT_BREAK_AFTER =
MUST_NOT_BREAK_BEFORE =
NO_BINARY_CHECK = true
SEGMENTATION = indexing
SEGMENTATION-all = full
SEGMENTATION-inner = inner
SEGMENTATION-outer = outer
SEGMENTATION-raw = none
SEGMENTATION-standard = standard
SHOULD_LINEMERGE = true
TRANSFORMS =
TRUNCATE = 10000
category = Structured
description = Infoblox capacity report from host
detect_trailing_nulls = false
disabled = false
maxDist = 100
priority =
pulldown_type = 1
sourcetype =
termFrequencyWeightedDist = false&lt;/LI-CODE&gt;&lt;P&gt;Even if I duplicate _json's exact settings for ibgrid, and assuming that works, the fact remains that the event itself still gets cut off at 349 lines.&amp;nbsp; Is there any reasoning to this?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 21:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573389#M101426</guid>
      <dc:creator>freza</dc:creator>
      <dc:date>2021-11-02T21:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573390#M101427</link>
      <description>&lt;P&gt;When you are doing diff for those definitions you see a difference.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;12c12
&amp;lt; INDEXED_EXTRACTIONS = none
---
&amp;gt; INDEXED_EXTRACTIONS = json&lt;/LI-CODE&gt;&lt;P&gt;Just add second line to your new definition and then it probably works.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 21:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573390#M101427</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-02T21:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573402#M101430</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion, I did update the settings on my custom sourcetype, ibcapacity, where the btool command was identical to that of _json's btool command, and it was doing exactly as before, linebreaking every line:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="LINUX-17194 pic2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16710iAC33D62A7EEFA431/image-size/large?v=v2&amp;amp;px=999" role="button" title="LINUX-17194 pic2.png" alt="LINUX-17194 pic2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure there is a line break issue here, but I'm not sure how to implement it.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 22:24:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573402#M101430</guid>
      <dc:creator>freza</dc:creator>
      <dc:date>2021-11-02T22:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573406#M101431</link>
      <description>This works ok if you have set sourcetype as _json ?</description>
      <pubDate>Tue, 02 Nov 2021 22:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573406#M101431</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-02T22:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573408#M101432</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;This works ok if you have set sourcetype as _json ?&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes and no, it works to display the log file as an event, but cuts it off at 349 lines, the file itself is 392 lines.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 22:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573408#M101432</guid>
      <dc:creator>freza</dc:creator>
      <dc:date>2021-11-02T22:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573411#M101433</link>
      <description>&lt;P&gt;I did something here, I put the props.conf on the ~local on the Splunk UF host where the script is being run:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ibcapacity]
ADD_EXTRA_TIME_FIELDS = True
ANNOTATE_PUNCT = True
AUTO_KV_JSON = true
BREAK_ONLY_BEFORE =
BREAK_ONLY_BEFORE_DATE =
CHARSET = AUTO
DATETIME_CONFIG =
DEPTH_LIMIT = 1000
DETERMINE_TIMESTAMP_DATE_WITH_SYSTEM_TIME = false
HEADER_MODE =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LB_CHUNK_BREAKER_TRUNCATE = 2000000
LEARN_MODEL = true
LEARN_SOURCETYPE = true
LINE_BREAKER = ([\r\n]+)
LINE_BREAKER_LOOKBEHIND = 100
MATCH_LIMIT = 100000
MAX_DAYS_AGO = 2000
MAX_DAYS_HENCE = 2
MAX_DIFF_SECS_AGO = 3600
MAX_DIFF_SECS_HENCE = 604800
MAX_EVENTS = 512
MAX_TIMESTAMP_LOOKAHEAD = 128
MUST_BREAK_AFTER =
MUST_NOT_BREAK_AFTER =
MUST_NOT_BREAK_BEFORE =
NO_BINARY_CHECK = true
SEGMENTATION = indexing
SEGMENTATION-all = full
SEGMENTATION-inner = inner
SEGMENTATION-outer = outer
SEGMENTATION-raw = none
SEGMENTATION-standard = standard
SHOULD_LINEMERGE = false
TRANSFORMS =
TRUNCATE = 10000
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
detect_trailing_nulls = false
disabled = false
maxDist = 100
priority =
pulldown_type = true
sourcetype =
termFrequencyWeightedDist = false&lt;/LI-CODE&gt;&lt;P&gt;and then restarted the Splunk UF on the host, and ran the script again...it did do the same exact thing as the _json sourcetype, where it cut it off at 349 lines.&amp;nbsp; So then I deleted about 60 lines and ensured that the brackets all closed, let the Splunk UF read the file again, and now it did perform the correct _json like parsing for the custom sourcetype, ibcapacity:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="It works, but only when the entire json file is less than 349 lines." style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16711i06161D436207D190/image-size/large?v=v2&amp;amp;px=999" role="button" title="LINUX-17194 pic3.png" alt="It works, but only when the entire json file is less than 349 lines." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;It works, but only when the entire json file is less than 349 lines.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there anyway to ensure that Splunk will read the entire 392 lines?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 22:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573411#M101433</guid>
      <dc:creator>freza</dc:creator>
      <dc:date>2021-11-02T22:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573435#M101435</link>
      <description>Maybe it’s TRUNCATE? How many character this 349 lines are?</description>
      <pubDate>Wed, 03 Nov 2021 06:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573435#M101435</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-03T06:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: help on custom sourcetype for log parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573827#M101488</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, it was a "TRUNCATE" value thing, my entire json file is more than 10,000 characters; so once I updated TRUNCATE = 15000, it worked.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 14:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/help-on-custom-sourcetype-for-log-parsing/m-p/573827#M101488</guid>
      <dc:creator>freza</dc:creator>
      <dc:date>2021-11-05T14:17:57Z</dc:date>
    </item>
  </channel>
</rss>

