<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder merges multiple events into one in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71625#M14598</link>
    <description>&lt;P&gt;Hi Ayn&lt;/P&gt;

&lt;P&gt;Can you tell me how to configure the settings in the indexer&lt;/P&gt;</description>
    <pubDate>Mon, 25 Mar 2013 13:47:03 GMT</pubDate>
    <dc:creator>sansri7680</dc:creator>
    <dc:date>2013-03-25T13:47:03Z</dc:date>
    <item>
      <title>Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71621#M14594</link>
      <description>&lt;P&gt;I have a file which is monitored by the Universal forwarder in Windows box. I installed the forwarder on windows using the msi installer. I have data coming into the file regularly and the format is as below&lt;/P&gt;

&lt;P&gt;INBOUND&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;  19:00:17:308 Eventid:153001(3)&lt;BR /&gt;
NAS Rx PDU, from 10.10.11.36:36412 to 10.10.11.226:36412 (42)&lt;/P&gt;

&lt;P&gt;Non Access Stratum (NAS) (42 bytes)&lt;BR /&gt;
  EPS Mobility Management&lt;BR /&gt;
    Protocol Discriminator&lt;BR /&gt;
       EPS MOBILITY MANAGEMENT MESSAGES(0x7)&lt;BR /&gt;
    Security Header Type&lt;BR /&gt;
       NAS_MSG_SECURITY_HDR_PLAIN_NAS_MSG(0x0)&lt;BR /&gt;
    Message Type&lt;BR /&gt;
       ATTACH_REQUEST(0x41)&lt;BR /&gt;
    Attach Type&lt;BR /&gt;
       EPS ATTACH(0x1)&lt;BR /&gt;
    Key Set Identifier&lt;BR /&gt;
       NO KEY AVAILABLE(0x7)&lt;BR /&gt;
    Mobile Identity&lt;BR /&gt;
        IMSI (240010000099935)&lt;BR /&gt;
    UE n/w capability&lt;BR /&gt;
      (0xe0e0)&lt;BR /&gt;
    ESM CONTAINER&lt;BR /&gt;
      EPS Session Management&lt;BR /&gt;
        Protocol Discriminator&lt;BR /&gt;
           EPS SESSION MANAGEMENT MESSAGES(0x2)&lt;BR /&gt;
        EPS Bearer Id&lt;BR /&gt;
          (0x0)&lt;BR /&gt;
        Transaction Id&lt;BR /&gt;
          (0x1)&lt;BR /&gt;
        Message Type&lt;BR /&gt;
           PDN_CONNECTIVITY_REQUEST(0xd0)&lt;BR /&gt;
        Request Type&lt;BR /&gt;
           INITIAL REQUEST(0x1)&lt;BR /&gt;
        PDN Type&lt;BR /&gt;
           IPv4(0x1)&lt;BR /&gt;
        Protocol Config Options&lt;BR /&gt;
           Configuration Protocol:&lt;BR /&gt;
             PPP&lt;BR /&gt;
           Proto/Container ID:&lt;BR /&gt;
             IPCP&lt;BR /&gt;
             Contents:0x0100000A810600000000&lt;BR /&gt;
    MS n/w capability&lt;BR /&gt;
      (0xc540f4)&lt;/P&gt;

&lt;P&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;OUTBOUND  19:00:17:730 Eventid:153002(3)&lt;BR /&gt;
NAS Tx PDU, from 10.10.11.226:36412 to 10.10.11.36:36412 (36)&lt;/P&gt;

&lt;P&gt;Non Access Stratum (NAS) (36 bytes)&lt;BR /&gt;
  EPS Mobility Management&lt;BR /&gt;
    Protocol Discriminator&lt;BR /&gt;
       EPS MOBILITY MANAGEMENT MESSAGES(0x7)&lt;BR /&gt;
    Security Header Type&lt;BR /&gt;
       NAS_MSG_SECURITY_HDR_PLAIN_NAS_MSG(0x0)&lt;BR /&gt;
    Message Type&lt;BR /&gt;
       AUTHENTICATION_REQUEST(0x52)&lt;BR /&gt;
    Key Set Identifier&lt;BR /&gt;
       Security Context Type: Native (0x0)&lt;BR /&gt;
       Key Set Index: (0x6)&lt;BR /&gt;
    Spare-Half&lt;BR /&gt;
      (0x0)&lt;BR /&gt;
    RAND&lt;BR /&gt;
      (0x81d97b15a0aa040081d97b15a0aa0400)&lt;BR /&gt;
    AUTN&lt;BR /&gt;
      (0x18f97648c158fffe445a366fe14f1160)&lt;/P&gt;

&lt;P&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;OUTBOUND  19:00:17:730 Eventid:155213(3)&lt;BR /&gt;
S1AP Tx PDU, from 10.10.11.226:36412 to 10.10.11.36:36412 (62)&lt;/P&gt;

&lt;P&gt;S1 Application Part (S1AP) (62 bytes)&lt;BR /&gt;
  | 0... .... | Ext bit : 0&lt;BR /&gt;
  | .00. .... | Choice index : Initiating Message (0)&lt;BR /&gt;
    Procedure Code :   DOWNLINK NAS TRANSPORT (11)&lt;BR /&gt;
    Criticality&lt;BR /&gt;
      | 01.. .... | Ignore (1)&lt;BR /&gt;
    DOWNLINK NAS TRANSPORT Value : &lt;BR /&gt;
      | .011 1010 | Length Determinant : 58&lt;BR /&gt;
      Value : &lt;BR /&gt;
        | 0... .... | Ext bit : 0&lt;BR /&gt;
          IEs Count : 3&lt;BR /&gt;
            IE : 1&lt;BR /&gt;
              Protocol IE ID : MME_UE_S1AP_ID (0)&lt;BR /&gt;
              Criticality&lt;BR /&gt;
                | 00.. .... | Reject (0)&lt;BR /&gt;
              MME_UE_S1AP_ID Value : &lt;BR /&gt;
                | .000 0100 | Length Determinant : 4&lt;BR /&gt;
                Value : &lt;BR /&gt;
                  | 10.. .... | Length Determinant : 3&lt;BR /&gt;
                  12582917 (0xc00005)&lt;BR /&gt;
            IE : 2&lt;BR /&gt;
              Protocol IE ID : eNB_UE_S1AP_ID (8)&lt;BR /&gt;
              Criticality&lt;BR /&gt;
                | 00.. .... | Reject (0)&lt;BR /&gt;
              eNB_UE_S1AP_ID Value : &lt;BR /&gt;
                | .000 0010 | Length Determinant : 2&lt;BR /&gt;
                Value : &lt;BR /&gt;
                  | 00.. .... | Length Determinant : 1&lt;BR /&gt;
                  13 (0x0d)&lt;BR /&gt;
            IE : 3&lt;BR /&gt;
              Protocol IE ID : NAS_PDU (26)&lt;BR /&gt;
              Criticality&lt;BR /&gt;
                | 00.. .... | Reject (0)&lt;BR /&gt;
              NAS_PDU Value : &lt;BR /&gt;
                | .010 0101 | Length Determinant : 37&lt;BR /&gt;
                Value : &lt;BR /&gt;
                  | .010 0100 | Length Determinant : 36&lt;BR /&gt;
                  0x07520681d97b15a0aa040081d97b15a0aa04001018f97648c158fffe445a366fe14f1160&lt;BR /&gt;
                    EPS Mobility Management&lt;BR /&gt;
                      Protocol Discriminator&lt;BR /&gt;
                         EPS MOBILITY MANAGEMENT MESSAGES(0x7)&lt;BR /&gt;
                      Security Header Type&lt;BR /&gt;
                         NAS_MSG_SECURITY_HDR_PLAIN_NAS_MSG(0x0)&lt;BR /&gt;
                      Message Type&lt;BR /&gt;
                         AUTHENTICATION_REQUEST(0x52)&lt;BR /&gt;
                      Key Set Identifier&lt;BR /&gt;
                         Security Context Type: Native (0x0)&lt;BR /&gt;
                         Key Set Index: (0x6)&lt;BR /&gt;
                      Spare-Half&lt;BR /&gt;
                        (0x0)&lt;BR /&gt;
                      RAND&lt;BR /&gt;
                        (0x81d97b15a0aa040081d97b15a0aa0400)&lt;BR /&gt;
                      AUTN&lt;BR /&gt;
                        (0x18f97648c158fffe445a366fe14f1160)&lt;/P&gt;

&lt;P&gt;My props.conf on my UNIX box is as below&lt;BR /&gt;
[4GCDR]&lt;BR /&gt;
BREAK_ONLY_BEFORE = (.*)(INBOUND&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;|&amp;lt;&amp;lt;&amp;lt;&amp;lt;OUTBOUND)&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
pulldown_type = 1&lt;BR /&gt;
TRUNCATE=0&lt;/P&gt;

&lt;P&gt;I created a UDP input to monitor the port where the windows forwarder sends the data&lt;/P&gt;

&lt;P&gt;But whenever more than one event occurs in the monitored file all the events are merged into a single event. If events are updated one by one there are no problems. Can someone please help &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71621#M14594</guid>
      <dc:creator>sansri7680</dc:creator>
      <dc:date>2020-09-28T13:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71622#M14595</link>
      <description>&lt;P&gt;Your break only before param should look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;BREAK_ONLY_BEFORE = ^(INBOUND&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;|&amp;lt;&amp;lt;&amp;lt;&amp;lt;OUTBOUND)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also for future reference you should probably use the data preview to generate the props.conf with test data. Go to Manager &amp;gt; Data inputs &amp;gt; Files &amp;amp; directories &amp;gt; new, upload the file and go into advanced settings. Make sure the events are being parsed out the way you want them to and then you can copy the parameters you have created into your existing props.conf.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 13:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71622#M14595</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2013-03-22T13:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71623#M14596</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;The props.conf settings that I used was fine if I upload a single file. But it is not working with the Universal forwarder&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 14:05:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71623#M14596</guid>
      <dc:creator>sansri7680</dc:creator>
      <dc:date>2013-03-22T14:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71624#M14597</link>
      <description>&lt;P&gt;Universal Forwarders do not perform event breaking, and so you should put these settings on the indexer, not the forwarder.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 14:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71624#M14597</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-22T14:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71625#M14598</link>
      <description>&lt;P&gt;Hi Ayn&lt;/P&gt;

&lt;P&gt;Can you tell me how to configure the settings in the indexer&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 13:47:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71625#M14598</guid>
      <dc:creator>sansri7680</dc:creator>
      <dc:date>2013-03-25T13:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71626#M14599</link>
      <description>&lt;P&gt;Just copy the props.conf that you posted into your indexer instead of your forwarder. Then restart your indexer&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 15:47:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71626#M14599</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2013-03-25T15:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71627#M14600</link>
      <description>&lt;P&gt;I tried that also. But no events are coming into splunk now&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2013 06:51:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71627#M14600</guid>
      <dc:creator>sansri7680</dc:creator>
      <dc:date>2013-03-26T06:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder merges multiple events into one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71628#M14601</link>
      <description>&lt;P&gt;We are going to need a bit more information if you want us to help you.&lt;/P&gt;

&lt;P&gt;Check your splunkd.log under $SPLUNK_HOME/var/log/splunk. Are there any error messages? Where did you save your props.conf? Have you defined your inputs.conf on both your forwarder and indexer properly? Have you defined your outputs.conf on your forwarder?&lt;/P&gt;

&lt;P&gt;Make sure you use the same sourcetype in your inputs.conf on your forwarder, and on the stanza header of your props.conf. Your sourcetype should be "4GCDR" based on what you put in the props.conf example you gave.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2013 14:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-merges-multiple-events-into-one/m-p/71628#M14601</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2013-03-26T14:15:02Z</dc:date>
    </item>
  </channel>
</rss>

