<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic single event for mutiple lines in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/single-event-for-mutiple-lines/m-p/643149#M109593</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am collecting metrics using API calls for every 5 minutes , but all the metrics are coming as a single event as below for every 5 minutes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="sa-r29997",type="Fetch",} 2092668.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="sa-9pyr8m",type="Metadata",} 1849.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="sa-r29997",type="Metadata",} 66279.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="u-09pr56",type="Metadata",} 0.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_response_bytes{kafka_id="rtrtt",principal_id="sa-y629ok",type="Fetch",} 5019.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_response_bytes{kafka_id="trtrt",principal_id="sa-8gg7jr",type="Metadata",} 0.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt",} 1.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt.enriched",} 1.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt.fulfilment.auto",} 1.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt.gg",} 0.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to break these events as individuals (which ever events starting from text “&lt;STRONG&gt;confluent_kafka_”)&lt;/STRONG&gt; &amp;nbsp;. I have edited my props.conf as below but its not coming as expected still its coming as a single event. Can some one please guide me how to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[source::kafka_metrics://kafka_metrics]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LINE_BREAKER = (confluent_kafka_)(\s)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SHOULD_LINEMERGE = false &lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2023 06:55:28 GMT</pubDate>
    <dc:creator>roopeshetty</dc:creator>
    <dc:date>2023-05-12T06:55:28Z</dc:date>
    <item>
      <title>single event for mutiple lines</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/single-event-for-mutiple-lines/m-p/643149#M109593</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am collecting metrics using API calls for every 5 minutes , but all the metrics are coming as a single event as below for every 5 minutes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="sa-r29997",type="Fetch",} 2092668.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="sa-9pyr8m",type="Metadata",} 1849.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="sa-r29997",type="Metadata",} 66279.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_request_bytes{kafka_id="tythtyt",principal_id="u-09pr56",type="Metadata",} 0.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_response_bytes{kafka_id="rtrtt",principal_id="sa-y629ok",type="Fetch",} 5019.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_response_bytes{kafka_id="trtrt",principal_id="sa-8gg7jr",type="Metadata",} 0.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt",} 1.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt.enriched",} 1.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt.fulfilment.auto",} 1.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;confluent_kafka_server_memory{kafka_id="yyyy",topic="host002.json.cs.tt.gg",} 0.0 1683872880000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to break these events as individuals (which ever events starting from text “&lt;STRONG&gt;confluent_kafka_”)&lt;/STRONG&gt; &amp;nbsp;. I have edited my props.conf as below but its not coming as expected still its coming as a single event. Can some one please guide me how to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[source::kafka_metrics://kafka_metrics]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LINE_BREAKER = (confluent_kafka_)(\s)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SHOULD_LINEMERGE = false &lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 06:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/single-event-for-mutiple-lines/m-p/643149#M109593</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-05-12T06:55:28Z</dc:date>
    </item>
  </channel>
</rss>

