<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the setting for TCP Line Breaking? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636273#M108830</link>
    <description>&lt;P&gt;what could be the settings to break the tcp data in splunk. Need to break after&amp;nbsp;@sign to another event.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;L2023087102901 some data&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@L2023087102903 another some data&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 14:29:53 GMT</pubDate>
    <dc:creator>JGP</dc:creator>
    <dc:date>2023-03-28T14:29:53Z</dc:date>
    <item>
      <title>What is the setting for TCP Line Breaking?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636273#M108830</link>
      <description>&lt;P&gt;what could be the settings to break the tcp data in splunk. Need to break after&amp;nbsp;@sign to another event.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;L2023087102901 some data&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt; &lt;SPAN class=""&gt;000000&lt;/SPAN&gt;&lt;SPAN&gt; &amp;lt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@L2023087102903 another some data&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636273#M108830</guid>
      <dc:creator>JGP</dc:creator>
      <dc:date>2023-03-28T14:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is the setting for TCP Line Breaking?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636310#M108834</link>
      <description>&lt;P&gt;Presuming you intend to break after the full string of&amp;nbsp;@'s then try this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = (@+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 17:00:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636310#M108834</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-28T17:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Line Breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636324#M108840</link>
      <description>&lt;P&gt;Tried, but it is removing all&amp;nbsp;@ sign data from the event&lt;/P&gt;&lt;P&gt;also wanted to have those entry as well in the event&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636324#M108840</guid>
      <dc:creator>JGP</dc:creator>
      <dc:date>2023-03-28T13:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Line Breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636373#M108851</link>
      <description>&lt;P&gt;OK then try this.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = @+()&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 28 Mar 2023 17:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636373#M108851</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-28T17:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is the setting for TCP Line Breaking?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636615#M108874</link>
      <description>&lt;P&gt;it worked.... thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 03:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/636615#M108874</guid>
      <dc:creator>JGP</dc:creator>
      <dc:date>2023-03-30T03:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is the setting for TCP Line Breaking?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/650878#M110575</link>
      <description>&lt;P&gt;probably this would be a solution&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 17:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-setting-for-TCP-Line-Breaking/m-p/650878#M110575</guid>
      <dc:creator>1783797</dc:creator>
      <dc:date>2023-07-17T17:39:09Z</dc:date>
    </item>
  </channel>
</rss>

