<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netscreen Firewall Syslog Input not line breaking in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76984#M15741</link>
    <description>&lt;P&gt;I know this problem has already been addressed but I cannot resolve the problem using the directions in 'Juniper Netscreen TCP Syslog messages not breaking properly'  &lt;/P&gt;

&lt;P&gt;I have added the entries in the two conf files as listed there&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;You also might need to set a line breaker defined in your sourcetype as
&lt;/CODE&gt;&lt;/PRE&gt;
  
  &lt;P&gt;follows
  $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;*[tcp://9999]
sourcetype = juniper_syslog_stuff
And In your $SPLUNK_HOME/etc/system/local/props.conf
[junpiper_syslog_stuff]
LINE_BREAKER=(\x00)&amp;lt;\d+&amp;gt;
SHOULD_LINEMERGE=False*
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;And changed the tcp to 1468 which is the port I am using.   This does not work and I still get the lines added together.  Looking at the actual log output in splunk I can see that the line break is different in my system \x00&amp;lt;133&amp;gt; but I have tried every possible permutation of that in the LINE_BREAKER expression and I cannot get it to work&lt;/P&gt;

&lt;P&gt;I am sure I am just being a muppet but some help would be appreciated&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;25/10/2010 19:55:00.000   &lt;/P&gt;
  
  &lt;P&gt;zone=Untrust dst zone=Trust
  action=Permit sent=887 rcvd=529
  src=93.189.29.26 dst=212.21.101.220
  src_port=52584 dst_port=80 src-xlated
  ip=93.189.29.26 port=52584 dst-xlated
  ip=212.21.101.220 port=80
  session_id=1824 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:56"
  duration=1 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=1312
  rcvd=12852 src=93.189.29.26
  dst=212.21.101.220 src_port=52588
  dst_port=80 src-xlated ip=93.189.29.26
  port=52588 dst-xlated
  ip=212.21.101.220 port=80
  session_id=3203 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=9 service=dns
  proto=17 src zone=Untrust dst
  zone=Trust action=Permit sent=83
  rcvd=215 src=195.96.0.4
  dst=212.21.101.193 src_port=47092
  dst_port=53 src-xlated ip=195.96.0.4
  port=47092 dst-xlated
  ip=212.21.101.193 port=53
  session_id=3973 reason=Close -
  RESP\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=3196
  rcvd=897 src=88.97.218.190
  dst=212.21.101.217 src_port=64015
  dst_port=80 src-xlated
  ip=88.97.218.190 port=64015 dst-xlated
  ip=212.21.101.217 port=80
  session_id=3983 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=9 service=dns
  proto=17 src zone=Untrust dst
  zone=Trust action=Permit sent=97
  rcvd=226 src=195.252.72.67
  dst=212.21.101.193 src_port=32768
  dst_port=53 src-xlated
  ip=195.252.72.67 port=32768 dst-xlated
  ip=212.21.101.193 port=53
  session_id=2524 reason=Close -
  RESP\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=7156
  rcvd=40647 src=79.173.154.37
  dst=212.46.132.46 src_port=53796
  dst_port=80 src-xlated
  ip=79.173.154.37 port=53796 dst-xlated
  ip=212.46.132.46 port=80
  session_id=2075 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:49"
  duration=8 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=3679
  rcvd=62167 src=79.173.154.37
  dst=212.46.132.46 src_port=53792
  dst_port=80 src-xlated
  ip=79.173.154.37 port=53792 dst-xlated
  ip=212.46.132.46 port=80
  session_id=3941 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=9 service=dns
  proto=17 src zone=Untrust dst
  zone=Trust action=Permit sent=97
  rcvd=178 src=203.135.190.6
  dst=212.21.101.193 src_port=5413
  dst_port=53 src-xlated
  ip=203.135.190.6 port=5413 dst-xlated
  ip=212.21.101.193 port=53
  session_id=2896 reason=Close -
  RESP\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34187
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34187 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3287 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34184
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34184 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2261 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34179
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34179 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3654 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34178
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34178 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3466 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34173
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34173 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2486 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34165
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34165 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2716 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34254
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34254 dst-xlated
  ip=212.46.132.46 port=443
  session_id=4043 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34249
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34249 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2318 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34248
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34248 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2625 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34241
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34241 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2467 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34226
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34226 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3831 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34218
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34218 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2672 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34210
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34210 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2063 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34203
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34203 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3326 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34197
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34197 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3637 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34194
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34194 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3175 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time=&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Mon, 25 Oct 2010 23:43:12 GMT</pubDate>
    <dc:creator>Dragonnet</dc:creator>
    <dc:date>2010-10-25T23:43:12Z</dc:date>
    <item>
      <title>Netscreen Firewall Syslog Input not line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76984#M15741</link>
      <description>&lt;P&gt;I know this problem has already been addressed but I cannot resolve the problem using the directions in 'Juniper Netscreen TCP Syslog messages not breaking properly'  &lt;/P&gt;

&lt;P&gt;I have added the entries in the two conf files as listed there&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;You also might need to set a line breaker defined in your sourcetype as
&lt;/CODE&gt;&lt;/PRE&gt;
  
  &lt;P&gt;follows
  $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;*[tcp://9999]
sourcetype = juniper_syslog_stuff
And In your $SPLUNK_HOME/etc/system/local/props.conf
[junpiper_syslog_stuff]
LINE_BREAKER=(\x00)&amp;lt;\d+&amp;gt;
SHOULD_LINEMERGE=False*
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;And changed the tcp to 1468 which is the port I am using.   This does not work and I still get the lines added together.  Looking at the actual log output in splunk I can see that the line break is different in my system \x00&amp;lt;133&amp;gt; but I have tried every possible permutation of that in the LINE_BREAKER expression and I cannot get it to work&lt;/P&gt;

&lt;P&gt;I am sure I am just being a muppet but some help would be appreciated&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;P&gt;25/10/2010 19:55:00.000   &lt;/P&gt;
  
  &lt;P&gt;zone=Untrust dst zone=Trust
  action=Permit sent=887 rcvd=529
  src=93.189.29.26 dst=212.21.101.220
  src_port=52584 dst_port=80 src-xlated
  ip=93.189.29.26 port=52584 dst-xlated
  ip=212.21.101.220 port=80
  session_id=1824 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:56"
  duration=1 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=1312
  rcvd=12852 src=93.189.29.26
  dst=212.21.101.220 src_port=52588
  dst_port=80 src-xlated ip=93.189.29.26
  port=52588 dst-xlated
  ip=212.21.101.220 port=80
  session_id=3203 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=9 service=dns
  proto=17 src zone=Untrust dst
  zone=Trust action=Permit sent=83
  rcvd=215 src=195.96.0.4
  dst=212.21.101.193 src_port=47092
  dst_port=53 src-xlated ip=195.96.0.4
  port=47092 dst-xlated
  ip=212.21.101.193 port=53
  session_id=3973 reason=Close -
  RESP\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=3196
  rcvd=897 src=88.97.218.190
  dst=212.21.101.217 src_port=64015
  dst_port=80 src-xlated
  ip=88.97.218.190 port=64015 dst-xlated
  ip=212.21.101.217 port=80
  session_id=3983 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=9 service=dns
  proto=17 src zone=Untrust dst
  zone=Trust action=Permit sent=97
  rcvd=226 src=195.252.72.67
  dst=212.21.101.193 src_port=32768
  dst_port=53 src-xlated
  ip=195.252.72.67 port=32768 dst-xlated
  ip=212.21.101.193 port=53
  session_id=2524 reason=Close -
  RESP\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=7156
  rcvd=40647 src=79.173.154.37
  dst=212.46.132.46 src_port=53796
  dst_port=80 src-xlated
  ip=79.173.154.37 port=53796 dst-xlated
  ip=212.46.132.46 port=80
  session_id=2075 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:49"
  duration=8 policy_id=6 service=http
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=3679
  rcvd=62167 src=79.173.154.37
  dst=212.46.132.46 src_port=53792
  dst_port=80 src-xlated
  ip=79.173.154.37 port=53792 dst-xlated
  ip=212.46.132.46 port=80
  session_id=3941 reason=Close - TCP
  FIN\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=9 service=dns
  proto=17 src zone=Untrust dst
  zone=Trust action=Permit sent=97
  rcvd=178 src=203.135.190.6
  dst=212.21.101.193 src_port=5413
  dst_port=53 src-xlated
  ip=203.135.190.6 port=5413 dst-xlated
  ip=212.21.101.193 port=53
  session_id=2896 reason=Close -
  RESP\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34187
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34187 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3287 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34184
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34184 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2261 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34179
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34179 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3654 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34178
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34178 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3466 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34173
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34173 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2486 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34165
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34165 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2716 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:55"
  duration=2 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34254
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34254 dst-xlated
  ip=212.46.132.46 port=443
  session_id=4043 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34249
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34249 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2318 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34248
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34248 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2625 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34241
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34241 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2467 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34226
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34226 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3831 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34218
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34218 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2672 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:54"
  duration=3 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34210
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34210 dst-xlated
  ip=212.46.132.46 port=443
  session_id=2063 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34203
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34203 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3326 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34197
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34197 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3637 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time="2010-10-25 17:19:53"
  duration=4 policy_id=6 service=https
  proto=6 src zone=Untrust dst
  zone=Trust action=Permit sent=194
  rcvd=130 src=217.147.95.3
  dst=212.46.132.46 src_port=34194
  dst_port=443 src-xlated
  ip=217.147.95.3 port=34194 dst-xlated
  ip=212.46.132.46 port=443
  session_id=3175 reason=Close - AGE
  OUT\x00&amp;lt;133&amp;gt;ssg5-serial: NetScreen
  device_id=0162102007000604 
  [Root]system-notification-00257(traffic):
  start_time=&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 25 Oct 2010 23:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76984#M15741</guid>
      <dc:creator>Dragonnet</dc:creator>
      <dc:date>2010-10-25T23:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Netscreen Firewall Syslog Input not line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76985#M15742</link>
      <description>&lt;P&gt;Sorted.   &lt;/P&gt;

&lt;P&gt;LINE_BREAKER=(&amp;lt;133&amp;gt;)&lt;/P&gt;

&lt;P&gt;Works just fine,  It does leave an entry of \x100 behind every reason= field and one day I will work out how to get rid of that.&lt;/P&gt;

&lt;P&gt;If anyone can tell me how to kill that I would be grateful&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2010 16:56:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76985#M15742</guid>
      <dc:creator>Dragonnet</dc:creator>
      <dc:date>2010-10-26T16:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Netscreen Firewall Syslog Input not line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76986#M15743</link>
      <description>&lt;P&gt;The &amp;lt;133&amp;gt; is the syslog "facility" and "level" encoded into the message.  The "\x00" is probably a null termination at the end of each message.  One of my questions would be is the "\x00" actually a 0x00 byte, or the bytes 0x5C 0x78 0x30 0x30?  A wireshark capture would tell you for sure.&lt;/P&gt;

&lt;P&gt;Once you know, you could update the LINE_BREAKER to eat it as well, or use a SEDCMD in props.conf to filter it out.&lt;/P&gt;

&lt;P&gt;Also, the &amp;lt;133&amp;gt; may not always have the digits "133" in it.  Generalizing your regexp to 1 to 3 digits inside the &amp;lt;&amp;gt;'s would make it work if the Netscreen sends a different syslog level for some reason.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE_BREAKER=(&amp;lt;\d{1,3}&amp;gt;)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Oct 2010 20:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Netscreen-Firewall-Syslog-Input-not-line-breaking/m-p/76986#M15743</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2010-10-27T20:54:51Z</dc:date>
    </item>
  </channel>
</rss>

