<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: line break to different entries in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698382#M115785</link>
    <description>&lt;P&gt;Please share your raw events and the configurations you have tried&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 08:35:49 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-09-06T08:35:49Z</dc:date>
    <item>
      <title>line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698380#M115784</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="arunkuriakose_0-1725610979258.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32565i29E99225FF2E85F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="arunkuriakose_0-1725610979258.png" alt="arunkuriakose_0-1725610979258.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have logs indexed like this. How to break entries based on each lines . i need each line as a seperate entry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to do this via line breaker but didnt succeed. Any method to do it via search after indexing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 08:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698380#M115784</guid>
      <dc:creator>arunkuriakose</dc:creator>
      <dc:date>2024-09-06T08:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698382#M115785</link>
      <description>&lt;P&gt;Please share your raw events and the configurations you have tried&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 08:35:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698382#M115785</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-09-06T08:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698432#M115787</link>
      <description>&lt;P&gt;There are several different issues touched here.&lt;/P&gt;&lt;P&gt;As you have already indexed data, you cannot break the events again and re-index them. You can, however manipulate your data during searching. But you will have to "break" the data into separate results on each search explicitly using search commands.&lt;/P&gt;&lt;P&gt;If you want newly ingested data properly broken and indexed as separate events you need to configure your ingestion settings properly. But that will only work on newly ingested data. Old data will stay as it was.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 21:32:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698432#M115787</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-06T21:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698434#M115788</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the response. If i can reindex the data how to apply line breaking settings effficiently to achieve this&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 22:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698434#M115788</guid>
      <dc:creator>arunkuriakose</dc:creator>
      <dc:date>2024-09-06T22:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698441#M115789</link>
      <description>&lt;P&gt;As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; said - show us your raw events and what have you tried so far because maybe your idea was OK but applied in a wrong place.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 08:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698441#M115789</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-07T08:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698537#M115800</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the response .&lt;/P&gt;
&lt;P&gt;sample logs: (these are coming as a single event as mentioned in screenshot)&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;zowin.exposed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;3600&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns1.dyna-ns.net.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;zowin.exposed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;3600&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns2.dyna-ns.net.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;zuckerberg.exposed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;3600&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns1.afternic.com.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;zuckerberg.exposed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;3600&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns2.afternic.com.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;zwiebeltvde.exposed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;3600&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns&lt;/SPAN&gt; &lt;SPAN class=""&gt;docks13.rzone.de.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;zwiebeltvde.exposed.&lt;/SPAN&gt; &lt;SPAN class=""&gt;3600&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ns&lt;/SPAN&gt; &lt;SPAN class=""&gt;shades01.rzone.de&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I am applying this on UF config . (/etc/system/local/propes.conf&lt;/P&gt;
&lt;P&gt;[zone_files]&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;LINE_BREAKER= ([\r\n]+)
SHOULD_LINEMERGE = false&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;~&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 14:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698537#M115800</guid>
      <dc:creator>arunkuriakose</dc:creator>
      <dc:date>2024-09-09T14:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698540#M115802</link>
      <description>&lt;P&gt;OK. Let's back up a little.&lt;/P&gt;&lt;P&gt;1. How are the events ingested? Read from files with a monitor input or any other way? (like HEC input or a modular input). You mention UF so I suspect monitor input(s) but I want to be sure.&lt;/P&gt;&lt;P&gt;2. I assume you meant props.conf, not propes.conf - that was just a typo here, right?&lt;/P&gt;&lt;P&gt;3. Line breaking is _not_ happening on the UF. You need to have your LINE_BREAKER defined on the first heavy component that the event passes through (if you're sending from UF directly to indexers, you need this setting on the indexers).&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 11:15:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698540#M115802</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-09T11:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: line break to different entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698598#M115805</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; Your comments helped. I&amp;nbsp; was applying this on the UF level and changing to indexers made it work. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 05:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-to-different-entries/m-p/698598#M115805</guid>
      <dc:creator>arunkuriakose</dc:creator>
      <dc:date>2024-09-10T05:40:13Z</dc:date>
    </item>
  </channel>
</rss>

