<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic event breaking not happening in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685302#M114337</link>
    <description>&lt;P&gt;HI SMEs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having problem where logs coming from one of the syslog server are getting clubbed into one single raw event &amp;amp; not getting split. Sharing the below. Rather splitting it into 3 diff events it is coming under one single event. Kindly suggest any possible work around&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apr 14 17:30:50 172.10.10.10 %ASA-2-106006: Deny inbound UDP from 10.20.30.40/51785 to 172.10.10.10/162 on interface AI-VO-PVT&lt;BR /&gt;Apr 14 17:30:50 10.20.30.40 12812500: RP/0/RP0/CPU0:Apr 14 17:30:50.489 IST: ifmgr[301]: %PK-5-UPDOWN : Line protocol on Interface GigabitEthernet0/0/0/18, changed state to Down&lt;BR /&gt;Apr 14 17:30:50 10.225.124.136 TMNX: 258900 Base LOGGER-MINOR-tmnxLogFileDeleted-2009 [acct-log-id 18 file-id 22]: Log file cf3:\acttt\actof1822-20240414-075.xml.gz on compact flash cf3 has been deleted&lt;BR /&gt;Apr 14 17:30:50 10.20.30.40 12812502: RP/0/RP0/CPU0:Apr 14 17:30:50.493 IST: fia_driver[334]: %PLATFORM-2_FAULT : Interface GigabitEthernet0/0/0/18, Detected Local Fault&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 11:52:01 GMT</pubDate>
    <dc:creator>pm2012</dc:creator>
    <dc:date>2024-04-24T11:52:01Z</dc:date>
    <item>
      <title>event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685302#M114337</link>
      <description>&lt;P&gt;HI SMEs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having problem where logs coming from one of the syslog server are getting clubbed into one single raw event &amp;amp; not getting split. Sharing the below. Rather splitting it into 3 diff events it is coming under one single event. Kindly suggest any possible work around&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apr 14 17:30:50 172.10.10.10 %ASA-2-106006: Deny inbound UDP from 10.20.30.40/51785 to 172.10.10.10/162 on interface AI-VO-PVT&lt;BR /&gt;Apr 14 17:30:50 10.20.30.40 12812500: RP/0/RP0/CPU0:Apr 14 17:30:50.489 IST: ifmgr[301]: %PK-5-UPDOWN : Line protocol on Interface GigabitEthernet0/0/0/18, changed state to Down&lt;BR /&gt;Apr 14 17:30:50 10.225.124.136 TMNX: 258900 Base LOGGER-MINOR-tmnxLogFileDeleted-2009 [acct-log-id 18 file-id 22]: Log file cf3:\acttt\actof1822-20240414-075.xml.gz on compact flash cf3 has been deleted&lt;BR /&gt;Apr 14 17:30:50 10.20.30.40 12812502: RP/0/RP0/CPU0:Apr 14 17:30:50.493 IST: fia_driver[334]: %PLATFORM-2_FAULT : Interface GigabitEthernet0/0/0/18, Detected Local Fault&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 11:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685302#M114337</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2024-04-24T11:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685312#M114338</link>
      <description>&lt;P&gt;That looks like 4 different events rather than 3.&amp;nbsp; Please confirm.&lt;/P&gt;&lt;P&gt;Please share the props.conf settings for that sourcetype.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 12:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685312#M114338</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-24T12:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685423#M114361</link>
      <description>&lt;P&gt;Yeah that's correct basically these are 4 events. I am putting the config taken from GUI below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pm2012_0-1714034945550.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30558i4430D61D48D3BEC9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pm2012_0-1714034945550.png" alt="pm2012_0-1714034945550.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pm2012_1-1714034994632.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30559i850B78B7F2267C2E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pm2012_1-1714034994632.png" alt="pm2012_1-1714034994632.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 08:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685423#M114361</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2024-04-25T08:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685430#M114362</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;please find the attached snaps as i am restricted to GUI&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 09:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685430#M114362</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2024-04-25T09:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685460#M114364</link>
      <description>&lt;P&gt;The LINE_BREAKER setting requires a capture group.&amp;nbsp; The group is where events will be split.&amp;nbsp; Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = ()\w{3}\s\d\d:\d\d&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 25 Apr 2024 12:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685460#M114364</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-25T12:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685547#M114367</link>
      <description>&lt;P&gt;I check this however it was not matching. don't you think it should be as below&lt;/P&gt;&lt;P&gt;()\w{3}\s\d+\s+\d+\:\d+\:\d+\s+&lt;/P&gt;&lt;P&gt;However post updating this as well it is not working. Does it work only for new events post changes or the historical one as well? and how often it gets updated (the config changes)&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 03:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685547#M114367</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2024-04-26T03:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: event breaking not happening</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685609#M114368</link>
      <description>&lt;P&gt;Either regex should work.&amp;nbsp; BTW, it's not necessary to escape the colons.&lt;/P&gt;&lt;P&gt;Any change to props.conf only affects new data.&amp;nbsp; Config changes made in the UI take effect immediately; changes made to .conf files take effect after a restart.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 11:51:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-breaking-not-happening/m-p/685609#M114368</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-26T11:51:20Z</dc:date>
    </item>
  </channel>
</rss>

