<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LINE_BREAKER- how to add in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-how-to-add/m-p/667750#M111965</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;with that data there shouldn’t be any needs for anything else than default line breaker. It seems to be an event per line.&lt;/P&gt;&lt;P&gt;Also \P should be just P as those two has totally different meanings.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2023 22:05:10 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-11-07T22:05:10Z</dc:date>
    <item>
      <title>LINE_BREAKER- how to add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-how-to-add/m-p/667748#M111964</link>
      <description>&lt;P&gt;How to add the&amp;nbsp;LINE_BREAKER in propd .conf for the below events to get it split to different events . Currently these are comign as combines together&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Path =567 xcss sdsf&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Path = 5673 dvgsdbdv&amp;nbsp; v&lt;/P&gt;&lt;P&gt;Path = 43343 dvddv&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried&lt;/P&gt;&lt;P&gt;LINE_BREAKER = ([\r\n]+)\Path&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = FALSE&lt;/P&gt;&lt;P&gt;But didnt worked&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 21:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-how-to-add/m-p/667748#M111964</guid>
      <dc:creator>ethanthomas</dc:creator>
      <dc:date>2023-11-07T21:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER- how to add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-how-to-add/m-p/667750#M111965</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;with that data there shouldn’t be any needs for anything else than default line breaker. It seems to be an event per line.&lt;/P&gt;&lt;P&gt;Also \P should be just P as those two has totally different meanings.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 22:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-how-to-add/m-p/667750#M111965</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-07T22:05:10Z</dc:date>
    </item>
  </channel>
</rss>

