<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to Split the events before parsing into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679590#M113553</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you tried SHOULD_LINEMERGE = false?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 13:31:01 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-03-05T13:31:01Z</dc:date>
    <item>
      <title>Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679578#M113550</link>
      <description>&lt;P&gt;This below mentioned lines are coming as a single event and not as separate events. So we want to get them splitted i.e.. It starts with IP and the end would be with Email field so after which it needs to be a separate next&amp;nbsp; event.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;IP:aa.bbb.ccc.ddd##Browser:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0##LoginSuccess Wire At:04-03-24 15:10:32##CookieFilePath:/xxx/yyy/abc.com/xyz/abc/forms/submitform/live/12345/98765_3598/clear.txt##ABC:12344564##Sessionid:xyz-a1-ddd_1##Form:xyz##Type:Live##LoginSuccess:Yes##SessionUserId:123##Email:xyz@google.com
IP:aa.bbb.ccc.ddd##Browser:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0##LoginSuccess Wire At:04-03-24 17:12:32##CookieFilePath:/xxx/yyy/abc.com/xyz/abc/forms/submitform/live/12345/1234_9564/clear.txt##ABC:12344564##Sessionid:xyz-a1-ddd_1##Form:xyz##Type:Live##LoginSuccess:Yes##SessionUserId:123##Email:xyz@google.com
IP:aa.bbb.ccc.ddd##Browser:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0##LoginSuccess Wire At:04-03-24 18:10:32##CookieFilePath:/xxx/yyy/abc.com/xyz/abc/forms/submitform/live/12345/9821_365/clear.txt##ABC:12344564##Sessionid:xyz-a1-ddd_1##Form:xyz##Type:Live##LoginSuccess:Yes##SessionUserId:123##Email:xyz@google.com
IP:aa.bbb.ccc.ddd##Browser:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0##LoginSuccess Wire At:04-03-24 20:10:32##CookieFilePath:/xxx/yyy/abc.com/xyz/abc/forms/submitform/live/12345/222_123/clear.txt##ABC:12344564##Sessionid:xyz-a1-ddd_1##Form:xyz##Type:Live##LoginSuccess:Yes##SessionUserId:123##Email:xyz@google.com&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;SO kindly let me know how can be get them splitted into separate events.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 08:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679578#M113550</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-03-22T08:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679590#M113553</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you tried SHOULD_LINEMERGE = false?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 13:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679590#M113553</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-05T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679597#M113557</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Yes i have updated the props.conf in the UF of the server. Since I don't have access to the Indexers it didnt worked. Since our Search head are hosted in Cloud and managed by Splunk Support.&lt;/P&gt;&lt;P&gt;So what should i need to do if i need to apply to Indexers directly.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 15:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679597#M113557</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-03-05T15:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679603#M113558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to associate SHOULD_LINEMERGE = false to the sourcetype of your data in the UFs and in the Splunk Cloud Search Heads.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 15:14:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679603#M113558</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-05T15:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679827#M113601</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;You can apply in the HF's if you have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1709739269664.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29630i1B8A7BC0C08C9B80/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1709739269664.png" alt="kiran_panchavat_0-1709739269664.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 15:35:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/679827#M113601</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2024-03-06T15:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/681648#M113894</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;As previously stated, I implemented the setting SHOULD_LINEMERGE = false in Splunk Cloud SH, which successfully resolved the issue. However, the logs contain HTML events, which are now being treated as individual events, resulting in difficulties extracting the desired fields. Could you please advise on how we can address this?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 08:16:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/681648#M113894</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2024-03-22T08:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/681649#M113895</link>
      <description>&lt;P&gt;Here are the setting for props.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE=false      #Should always be false
LINE_BREAKER=([\r\n]+)IP    #Adds IP to the line breaking (If all lines starts with IP)
NO_BINARY_CHECK=true
TIME_FORMAT=%e-%m-%y %T     #Sets the time format
TIME_PREFIX=At:             #Use time found after the At:
MAX_TIMESTAMP_LOOKAHEAD=20  #Do not search more tha needed for the time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 09:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/681649#M113895</guid>
      <dc:creator>jotne</dc:creator>
      <dc:date>2024-03-22T09:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Need to Split the events before parsing into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/681656#M113899</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is the new MASA diagram where you could look where to put those and in which server&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/files/U0483CQG4/F06PKREDNLW/masa.pdf?origin_team=T047WPASC&amp;amp;origin_channel=Psearch" target="_blank"&gt;https://splunk-usergroups.slack.com/files/U0483CQG4/F06PKREDNLW/masa.pdf?origin_team=T047WPASC&amp;amp;origin_channel=Psearch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 09:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-Split-the-events-before-parsing-into-Splunk/m-p/681656#M113899</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-22T09:22:41Z</dc:date>
    </item>
  </channel>
</rss>

