<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex to Normalize data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597317#M104276</link>
    <description>&lt;P&gt;Thanks for the suggestion. I will definitely have a look at this. Meanwhile can you share me what config change i can make on the indexer.&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2022 07:39:40 GMT</pubDate>
    <dc:creator>ramprakash</dc:creator>
    <dc:date>2022-05-11T07:39:40Z</dc:date>
    <item>
      <title>Help with configuration: How to use Regex to Normalize data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597304#M104268</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;I have a requirement to parse the data correctly. I am getting merged events and wants separate events for the below events. Could someone help me what configuration needs to be changed and how can i learn regex.&lt;/P&gt;
&lt;P&gt;I need events to break from&amp;nbsp;&lt;SPAN&gt;[22/05/11@08:13:58.246+0200] P-20316642 T-000001....Timeframe, P and T values can be different. Appreciate your help&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[22/05/11@08:14:25.252+0200] P-37945744 T-000001 1 AS -- (Procedure: 'olb-stp-monitoring.r' Line:273) DML TRACE ERROR : use of refreshUsrRig , decomissioning ongoing&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[22/05/11@08:14:03.266+0200] P-29491506 T-000001 1 AS -- (Procedure: 'olb-stp-monitoring.r' Line:273) DML TRACE ERROR : use of refreshUsrRig , decomissioning ongoing&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[22/05/11@08:13:58.246+0200] P-20316642 T-000001 1 AS -- (Procedure: 'olb-stp-monitoring.r' Line:273) DML TRACE ERROR : use of refreshUsrRig , decomissioning ongoing&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 22:49:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597304#M104268</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T22:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597308#M104269</link>
      <description>&lt;P&gt;First question is - where are you getting those events from. If it's - for example - file source, it's about setting proper line breakers in props.conf. If they are coming in from HEC and they are pushed this way... Well, you can't do much about it - you should check the source.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 07:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597308#M104269</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-11T07:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597315#M104274</link>
      <description>&lt;P&gt;For the regex side of things, regex101.com is a good place to practice regex - however, it is worth noting that the way Splunk implements regex, particularly in searches, often requires additional escaping beyond what regex101 deems as a correct regex expression particularly for backslashes.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 07:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597315#M104274</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-11T07:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597316#M104275</link>
      <description>&lt;P&gt;It is coming fro the source file. Do you happen to know what props.conf i can use here.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 07:38:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597316#M104275</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T07:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597317#M104276</link>
      <description>&lt;P&gt;Thanks for the suggestion. I will definitely have a look at this. Meanwhile can you share me what config change i can make on the indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 07:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597317#M104276</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T07:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597321#M104277</link>
      <description>&lt;P&gt;The default line breaker should break the contents into multiple events so the question is what are your current settings - do you have something set explicitly for this sourcetype?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 07:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597321#M104277</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-11T07:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597325#M104278</link>
      <description>&lt;P&gt;No. I have not setup anything yet. The weird thing is some events are parsing correctly and some are bring merged&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 08:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597325#M104278</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T08:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597332#M104279</link>
      <description>&lt;P&gt;Check your source file. The default line breaker is ([\r\n]+) so it should match any end-of-line character sequence.&lt;/P&gt;&lt;P&gt;Use btool to verify your config (both on UF - see if it sets proper sourcetype, and on indexer(s) - verify the settings for that sourcetype/source/host).&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 08:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597332#M104279</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-11T08:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597340#M104280</link>
      <description>&lt;P&gt;As of now now I don't find t&lt;SPAN&gt;he default line breaker is ([\r\n]+)&amp;nbsp;in any sourcetype.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can I put it under sourcetype of both UF and Indexer and try again ?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 08:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597340#M104280</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T08:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597341#M104281</link>
      <description>&lt;P&gt;Interesting. I always thought it's explicitly specified in the default props.conf but I see (on my installation) that it isn't.&lt;/P&gt;&lt;P&gt;Try adding it on the indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 08:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597341#M104281</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-11T08:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597351#M104284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/150271"&gt;@ramprakash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you want a line or event break before the date&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;[22/05/11@08:13:58.246+0200]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;you could use either of the below setting&amp;nbsp; in props.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;BREAK_ONLY_BEFORE_DATE = true&lt;/P&gt;&lt;P&gt;OR&amp;nbsp;&lt;/P&gt;&lt;P&gt;BREAK_ONLY_BEFORE=&amp;lt;regex&amp;gt;&lt;/P&gt;&lt;P&gt;inyour case should be something like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;BREAK_ONLY_BEFORE=\[[\d+\/]+@[\d+:]+.\d+\+\d+\]&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 10:03:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597351#M104284</guid>
      <dc:creator>venky1544</dc:creator>
      <dc:date>2022-05-11T10:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597354#M104285</link>
      <description>&lt;P&gt;Thanks you so much and I assume I need to make the changes at UF level only or at the Indexer(In that case I will contact Splunk support]&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 10:30:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597354#M104285</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T10:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597358#M104287</link>
      <description>&lt;P&gt;Line breaking is done on the indexer/heavy-forwarder level (depending on whether you use HF's or not in your path of events). So you need to push your settings there. In case of the Splunk Cloud, where you don't have direct access to the indexers, you need to prepare and deploy an app containing the settings.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 10:41:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597358#M104287</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-11T10:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597363#M104289</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/150271"&gt;@ramprakash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is your instance on splunk cloud&amp;nbsp; if yes and you do have to contact the splunk support and if you have splunk enterprise on premise or splunk enterpise on cloud then you need to do it on the indexer not on forwarder and in HF(if you have this component and files are processing through HF)&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;&lt;P&gt;P.S if it helps karms points are appreciated/if it resolves solution acceptance is appreciated&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 11:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597363#M104289</guid>
      <dc:creator>venky1544</dc:creator>
      <dc:date>2022-05-11T11:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597397#M104299</link>
      <description>&lt;P&gt;Thanks for the solution. Let me check with the Support team as the instance is on Splunk cloud.&lt;/P&gt;&lt;P&gt;So I just need to provide them the sourcetype and the config that's all and they will make the changes on our behalf ?&lt;/P&gt;&lt;P&gt;We have UF Intermediate forwarder in between, I don't think so that's gonna be any issue.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 13:35:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597397#M104299</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2022-05-11T13:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Regex to Normalize data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597400#M104301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/150271"&gt;@ramprakash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it should be pretty straight forward you provide them the config details and they should be able to do it&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;venky&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 13:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-configuration-How-to-use-Regex-to-Normalize-data/m-p/597400#M104301</guid>
      <dc:creator>venky1544</dc:creator>
      <dc:date>2022-05-11T13:39:59Z</dc:date>
    </item>
  </channel>
</rss>

