<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic event line break in props in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/704999#M116609</link>
    <description>&lt;LI-CODE lang="markup"&gt;---------------------------- This is an Example (He/She) -----------------------------
Version:		21.04.812-174001 
Date/time:		2024-10-18/01:00:06 (2024-10-18/05:00:06 UTC)
User/aplnid:		/2370
ComputerName/-user:	Ann/King
Windows NT version 6.2, build no. 9200 /10872/6241785241
-&amp;gt; Loading program
----------------------------------------------------------------------------------------------------

---------------------------- This is an Example (He/She) -----------------------------
Version:		21.04.812-174001 
Date/time:		2024-10-18/01:00:06 (2024-10-18/05:00:06 UTC)
User/aplnid:		/2370
ComputerName/-user:	James/Bond
Windows NT version 6.2, build no. 9200 /10872/6241785241
-&amp;gt; Start APL (pid 8484)
----------------------------------------------------------------------------------------------------

---------------------------- This is an Example (He/She) -----------------------------
Version:		21.04.812-174001 
Date/time:		2024-10-18/01:00:06 (2024-10-18/05:00:06 UTC)
User/aplnid:		/2370
ComputerName/-user:	Martin/King
Windows NT version 6.2, build no. 9200 /10872/6241785241
-&amp;gt; Initialising external processes
----------------------------------------------------------------------------------------------------&lt;/LI-CODE&gt;&lt;P&gt;I am trying to break events at "This is an Example"&amp;nbsp;&lt;/P&gt;&lt;P&gt;[mysourcetype]&lt;BR /&gt;TIME_FORMAT = %Y-%m-%d/%H:%M:%S&lt;BR /&gt;TIME_PREFIX = Date\/time:\s+&lt;BR /&gt;TZ = US/Eastern&lt;BR /&gt;LINE_BREAKER = (.*)(This is An Example).*&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This works when i test in "Add Data" but it is not working under props.conf. All the lines are merged into one event. What is the issue in this?&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2024 21:31:11 GMT</pubDate>
    <dc:creator>narenpg</dc:creator>
    <dc:date>2024-11-21T21:31:11Z</dc:date>
    <item>
      <title>event line break in props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/704999#M116609</link>
      <description>&lt;LI-CODE lang="markup"&gt;---------------------------- This is an Example (He/She) -----------------------------
Version:		21.04.812-174001 
Date/time:		2024-10-18/01:00:06 (2024-10-18/05:00:06 UTC)
User/aplnid:		/2370
ComputerName/-user:	Ann/King
Windows NT version 6.2, build no. 9200 /10872/6241785241
-&amp;gt; Loading program
----------------------------------------------------------------------------------------------------

---------------------------- This is an Example (He/She) -----------------------------
Version:		21.04.812-174001 
Date/time:		2024-10-18/01:00:06 (2024-10-18/05:00:06 UTC)
User/aplnid:		/2370
ComputerName/-user:	James/Bond
Windows NT version 6.2, build no. 9200 /10872/6241785241
-&amp;gt; Start APL (pid 8484)
----------------------------------------------------------------------------------------------------

---------------------------- This is an Example (He/She) -----------------------------
Version:		21.04.812-174001 
Date/time:		2024-10-18/01:00:06 (2024-10-18/05:00:06 UTC)
User/aplnid:		/2370
ComputerName/-user:	Martin/King
Windows NT version 6.2, build no. 9200 /10872/6241785241
-&amp;gt; Initialising external processes
----------------------------------------------------------------------------------------------------&lt;/LI-CODE&gt;&lt;P&gt;I am trying to break events at "This is an Example"&amp;nbsp;&lt;/P&gt;&lt;P&gt;[mysourcetype]&lt;BR /&gt;TIME_FORMAT = %Y-%m-%d/%H:%M:%S&lt;BR /&gt;TIME_PREFIX = Date\/time:\s+&lt;BR /&gt;TZ = US/Eastern&lt;BR /&gt;LINE_BREAKER = (.*)(This is An Example).*&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This works when i test in "Add Data" but it is not working under props.conf. All the lines are merged into one event. What is the issue in this?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 21:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/704999#M116609</guid>
      <dc:creator>narenpg</dc:creator>
      <dc:date>2024-11-21T21:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: event line break in props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705002#M116610</link>
      <description>&lt;P&gt;1. Are you sure the LINE_BREAKER is right? I mean - the capture group in the LINE_BREAKER will be treated as the line breaker and will be removed from the stream. Are you sure you want to cut this much? Not more, not less? Also you usually include \r and/or \n explicitly in your line breaker definition. Otherwise the results might not be what you expect.&lt;/P&gt;&lt;P&gt;2. Are you sure you're putting your props.conf on the proper component in your environment?&lt;/P&gt;&lt;P&gt;3. Did you verify with btool that there is no other setting overwriting your line breaker?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 21:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705002#M116610</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-21T21:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: event line break in props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705005#M116611</link>
      <description>&lt;P&gt;1. It truncates hyphen - before the "This is an Example" now i added ([\r\n+])(.*)(This is an Example).* it captures everthing. But the events are broken into single lines. I have set SHOULD_LINE_MERGE = false.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Yes props.conf is on the proper component&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; i verified using this command&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; splunk btool inputs list --debug&amp;nbsp; (there is no other setting that is overwriting LINE_BREAKER)&lt;/P&gt;&lt;P&gt;NOTE:&amp;nbsp; can i use BREAK_ONLY_BEFORE instead of LINE_BREAKER&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 22:33:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705005#M116611</guid>
      <dc:creator>narenpg</dc:creator>
      <dc:date>2024-11-21T22:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: event line break in props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705017#M116612</link>
      <description>&lt;P&gt;1. OK. It's just that I'd probably just cut the whole "This is an example" line if it's just a constant delimiter between the events.&lt;/P&gt;&lt;P&gt;2. Where? And what does your ingestion process look like?&lt;/P&gt;&lt;P&gt;3. LINE_BREAKER is not defined at input level. It's defined in props but I'm assuming you meant "splunk btool props list", not inputs. If not, check props, not inputs.&lt;/P&gt;&lt;P&gt;BREAK_ONLY_BEFORE is a setting used only when SHOULD_LINEMERGE is set to true and that case is best avoided (there are very very rare cases where it makes sense; if possible, avoid enabling line-merging)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 09:48:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705017#M116612</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-22T09:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: event line break in props</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705044#M116619</link>
      <description>&lt;P&gt;1. Yes This is the constant delimiter ---------------------------- This is an Example (He/She) -----------------------------&lt;/P&gt;&lt;P&gt;2. It picks up every 7th line and skips others. I think that is because i used \n+ right?&lt;BR /&gt;3. I should have used "splunk btool props list" instead of inputs.. I ran the command and i see only one LINE_BREAKER for that sourcetype.&lt;/P&gt;&lt;P&gt;Thanks for the info on BREAK_ONLY_BEFORE&lt;/P&gt;&lt;P&gt;What is the Regex i should use it on the LINE_BREAKER?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/event-line-break-in-props/m-p/705044#M116619</guid>
      <dc:creator>narenpg</dc:creator>
      <dc:date>2024-11-22T15:03:19Z</dc:date>
    </item>
  </channel>
</rss>

