<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure line breaks for multiline events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-line-breaks-for-multiline-events/m-p/127567#M26215</link>
    <description>&lt;P&gt;Line Breaks in MultiLine Events ?&lt;/P&gt;

&lt;P&gt;Line Breakers&lt;BR /&gt;
BeforeJob and Start Backup&lt;BR /&gt;
Job ID is Unique&lt;BR /&gt;
Sample log is 3 events.&lt;/P&gt;

&lt;P&gt;If BeforeJob is on a line, break before BeforeJob and do not line break before Start Backup on first occurence of Start Backup&lt;/P&gt;

&lt;P&gt;Tried but rules conflict: Need expression for BeforeJob&lt;BR /&gt;
BREAK_ONLY_BEFORE = BeforeJob | Start Backup&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 300&lt;BR /&gt;
MUST_NOT_BREAK_AFTER = BeforeJob&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
pulldown_type = 1&lt;/P&gt;

&lt;P&gt;01-Jul 22:08 apsrd2058-dir JobId 210: End auto prune.&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: shell command: run BeforeJob "/etc/bareos/make_catalog_backup_uhg.pl MyCatalog"&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Start Backup JobId 211, Job=BackupCatalog.2014-07-01_23.10.00_28&lt;/P&gt;

&lt;P&gt;Sample Log:&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Start Backup JobId 210, Job=DBSRP0154-mySql-system-catalogs.2014-07-01_22.05.00_27&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Using Device "FileChgr3-Dev1" to write.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Volume "OPV0037" previously written, moving to end of data.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Ready to append to end of Volume "OPV0037" size=890611883&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Elapsed time=00:00:01, Transfer rate=119.9 K Bytes/second&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Sending spooled attrs to the Director. Despooling 309 bytes ...&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Bareos apsrd2058-dir 13.2.2 (12Nov13):&lt;BR /&gt;
  Build OS:               x86_64-unknown-linux-gnu redhat Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  JobId:                  210&lt;BR /&gt;
  Job:                    DBSRP0154-mySql-system-catalogs.2014-07-01_22.05.00_27&lt;BR /&gt;
  Backup Level:           Full&lt;BR /&gt;
  Client:                 "dbsrp0154-fd" 5.0.3 (04Aug10) x86_64-koji-linux-gnu,redhat,&lt;BR /&gt;
  FileSet:                "mysql system catalog set" 2014-06-25 22:05:04&lt;BR /&gt;
  Pool:                   "File" (From Job resource)&lt;BR /&gt;
  Catalog:                "MyCatalog" (From Client resource)&lt;BR /&gt;
  Storage:                "File3" (From Job resource)&lt;BR /&gt;
  Scheduled time:         01-Jul-2014 22:05:00&lt;BR /&gt;
  Start time:             01-Jul-2014 22:08:03&lt;BR /&gt;
  End time:               01-Jul-2014 22:08:04&lt;BR /&gt;
  Elapsed time:           1 sec&lt;BR /&gt;
  Priority:               10&lt;BR /&gt;
  FD Files Written:       1&lt;BR /&gt;
  SD Files Written:       1&lt;BR /&gt;
  FD Bytes Written:       119,761 (119.7 KB)&lt;BR /&gt;
  SD Bytes Written:       119,964 (119.9 KB)&lt;BR /&gt;
  Rate:                   119.8 KB/s&lt;BR /&gt;
  Software Compression:   None&lt;BR /&gt;
  VSS:                    no&lt;BR /&gt;
  Encryption:             no&lt;BR /&gt;
  Accurate:               no&lt;BR /&gt;
  Volume name(s):         OPV0037&lt;BR /&gt;
  Volume Session Id:      71&lt;BR /&gt;
  Volume Session Time:    1403751883&lt;BR /&gt;
  Last Volume Bytes:      890,732,465 (890.7 MB)&lt;BR /&gt;
  Non-fatal FD errors:    0&lt;BR /&gt;
  SD Errors:              0&lt;BR /&gt;
  FD termination status:  OK&lt;BR /&gt;
  SD termination status:  OK&lt;BR /&gt;
  Termination:            Backup OK&lt;/P&gt;

&lt;P&gt;01-Jul 22:08 apsrd2058-dir JobId 210: Begin pruning Jobs older than 1 month .&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: No Jobs found to prune.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Begin pruning Files.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: No Files found to prune.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: End auto prune.&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: shell command: run BeforeJob "/etc/bareos/make_catalog_backup_uhg.pl MyCatalog"&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Start Backup JobId 211, Job=BackupCatalog.2014-07-01_23.10.00_28&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Using Device "FileChgr3-Dev1" to write.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Volume "OPV0037" previously written, moving to end of data.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Ready to append to end of Volume "OPV0037" size=890732465&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Elapsed time=00:00:01, Transfer rate=25.14 M Bytes/second&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Sending spooled attrs to the Director. Despooling 293 bytes ...&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Bareos apsrd2058-dir 13.2.2 (12Nov13):&lt;BR /&gt;
  Build OS:               x86_64-unknown-linux-gnu redhat Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  JobId:                  211&lt;BR /&gt;
  Job:                    BackupCatalog.2014-07-01_23.10.00_28&lt;BR /&gt;
  Backup Level:           Full&lt;BR /&gt;
  Client:                 "apsrd2058-fd" 13.2.2 (12Nov13) x86_64-unknown-linux-gnu,redhat,Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  FileSet:                "Catalog" 2014-06-25 22:25:22&lt;BR /&gt;
  Pool:                   "File" (From Job resource)&lt;BR /&gt;
  Catalog:                "MyCatalog" (From Client resource)&lt;BR /&gt;
  Storage:                "File3" (From Job resource)&lt;BR /&gt;
  Scheduled time:         01-Jul-2014 23:10:00&lt;BR /&gt;
  Start time:             01-Jul-2014 23:10:03&lt;BR /&gt;
  End time:               01-Jul-2014 23:10:04&lt;BR /&gt;
  Elapsed time:           1 sec&lt;BR /&gt;
  Priority:               11&lt;BR /&gt;
  FD Files Written:       1&lt;BR /&gt;
  SD Files Written:       1&lt;BR /&gt;
  FD Bytes Written:       25,146,795 (25.14 MB)&lt;BR /&gt;
  SD Bytes Written:       25,146,914 (25.14 MB)&lt;BR /&gt;
  Rate:                   25146.8 KB/s&lt;BR /&gt;
  Software Compression:   None&lt;BR /&gt;
  VSS:                    no&lt;BR /&gt;
  Encryption:             no&lt;BR /&gt;
  Accurate:               no&lt;BR /&gt;
  Volume name(s):         OPV0037&lt;BR /&gt;
  Volume Session Id:      72&lt;BR /&gt;
  Volume Session Time:    1403751883&lt;BR /&gt;
  Last Volume Bytes:      915,898,455 (915.8 MB)&lt;BR /&gt;
  Non-fatal FD errors:    0&lt;BR /&gt;
  SD Errors:              0&lt;BR /&gt;
  FD termination status:  OK&lt;BR /&gt;
  SD termination status:  OK&lt;BR /&gt;
  Termination:            Backup OK&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: Begin pruning Jobs older than 2 months .&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: No Jobs found to prune.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Begin pruning Files.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Pruned Files from 1 Jobs for client apsrd2058-fd from catalog.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: End auto prune.&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: shell command: run AfterJob "/etc/bareos/delete_catalog_backup_uhg"&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + db_name=BUAASbareos&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + wd=/var/lib/bareos&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + max_versions=5&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + max_days=7&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: ++ find /var/lib/bareos -name '*BUAASbareos*sql'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: ++ wc -l&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: find: failed to restore initial working directory: Permission denied&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + filecount=11&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + echo 'filecount = 11'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: filecount = 11&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + '[' 11 -gt 5 ']'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + find /var/lib/bareos -name '*BUAASbareos*sql' -ctime +7 -exec rm -f '{}' ';'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: find: failed to restore initial working directory: Permission denied&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + '[' -f /var/lib/bareos/BUAASbareos.sql ']'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + rm -f /var/lib/bareos/BUAASbareos.sql&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Start Backup JobId 212, Job=DBSED1397-SqlServer.2014-07-02_21.10.00_29&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Using Device "FileChgr3-Dev1" to write.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Volume "OPV0037" previously written, moving to end of data.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Ready to append to end of Volume "OPV0037" size=915898455&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: Generate VSS snapshots. Driver="Win64 VSS", Drive(s)="E"&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Task Scheduler Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "VSS Metadata Store Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Performance Counters Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "System Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "SqlServerWriter", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "ASR Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Shadow Copy Optimization Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Registry Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "BITS Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "COM+ REGDB Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "WMI Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Elapsed time=00:00:13, Transfer rate=34.21 K Bytes/second&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Sending spooled attrs to the Director. Despooling 1,130 bytes ...&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Bareos apsrd2058-dir 13.2.2 (12Nov13):&lt;BR /&gt;
  Build OS:               x86_64-unknown-linux-gnu redhat Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  JobId:                  212&lt;BR /&gt;
  Job:                    DBSED1397-SqlServer.2014-07-02_21.10.00_29&lt;BR /&gt;
  Backup Level:           Full&lt;BR /&gt;
  Client:                 "dbsed1397-fd" 5.2.10 (28Jun12) Microsoft Windows Server 2008 R2 Enterprise Edition Service Pack 1 (build 7601), 64-bit,Cross-compile,Win64&lt;BR /&gt;
  FileSet:                "SQL Server Set" 2014-06-25 21:36:10&lt;BR /&gt;
  Pool:                   "File" (From Job resource)&lt;BR /&gt;
  Catalog:                "MyCatalog" (From Client resource)&lt;BR /&gt;
  Storage:                "File3" (From Job resource)&lt;BR /&gt;
  Scheduled time:         02-Jul-2014 21:10:00&lt;BR /&gt;
  Start time:             02-Jul-2014 21:10:03&lt;BR /&gt;
  End time:               02-Jul-2014 21:10:17&lt;BR /&gt;
  Elapsed time:           14 secs&lt;BR /&gt;
  Priority:               10&lt;BR /&gt;
  FD Files Written:       3&lt;BR /&gt;
  SD Files Written:       3&lt;BR /&gt;
  FD Bytes Written:       443,984 (443.9 KB)&lt;BR /&gt;
  SD Bytes Written:       444,742 (444.7 KB)&lt;BR /&gt;
  Rate:                   31.7 KB/s&lt;BR /&gt;
  Software Compression:   85.7 % (gzip)&lt;BR /&gt;
  VSS:                    yes&lt;BR /&gt;
  Encryption:             no&lt;BR /&gt;
  Accurate:               no&lt;BR /&gt;
  Volume name(s):         OPV0037&lt;BR /&gt;
  Volume Session Id:      73&lt;BR /&gt;
  Volume Session Time:    1403751883&lt;BR /&gt;
  Last Volume Bytes:      916,344,491 (916.3 MB)&lt;BR /&gt;
  Non-fatal FD errors:    0&lt;BR /&gt;
  SD Errors:              0&lt;BR /&gt;
  FD termination status:  OK&lt;BR /&gt;
  SD termination status:  OK&lt;BR /&gt;
  Termination:            Backup OK&lt;/P&gt;

&lt;P&gt;02-Jul 21:10 apsrd2058-dir JobId 212: Begin pruning Jobs older than 12 months .&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: No Jobs found to prune.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Begin pruning Files.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: No Files found to prune.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: End auto prune.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:36:21 GMT</pubDate>
    <dc:creator>paqua77</dc:creator>
    <dc:date>2020-09-28T17:36:21Z</dc:date>
    <item>
      <title>How to configure line breaks for multiline events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-line-breaks-for-multiline-events/m-p/127567#M26215</link>
      <description>&lt;P&gt;Line Breaks in MultiLine Events ?&lt;/P&gt;

&lt;P&gt;Line Breakers&lt;BR /&gt;
BeforeJob and Start Backup&lt;BR /&gt;
Job ID is Unique&lt;BR /&gt;
Sample log is 3 events.&lt;/P&gt;

&lt;P&gt;If BeforeJob is on a line, break before BeforeJob and do not line break before Start Backup on first occurence of Start Backup&lt;/P&gt;

&lt;P&gt;Tried but rules conflict: Need expression for BeforeJob&lt;BR /&gt;
BREAK_ONLY_BEFORE = BeforeJob | Start Backup&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 300&lt;BR /&gt;
MUST_NOT_BREAK_AFTER = BeforeJob&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
pulldown_type = 1&lt;/P&gt;

&lt;P&gt;01-Jul 22:08 apsrd2058-dir JobId 210: End auto prune.&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: shell command: run BeforeJob "/etc/bareos/make_catalog_backup_uhg.pl MyCatalog"&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Start Backup JobId 211, Job=BackupCatalog.2014-07-01_23.10.00_28&lt;/P&gt;

&lt;P&gt;Sample Log:&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Start Backup JobId 210, Job=DBSRP0154-mySql-system-catalogs.2014-07-01_22.05.00_27&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Using Device "FileChgr3-Dev1" to write.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Volume "OPV0037" previously written, moving to end of data.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Ready to append to end of Volume "OPV0037" size=890611883&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Elapsed time=00:00:01, Transfer rate=119.9 K Bytes/second&lt;BR /&gt;
01-Jul 22:08 apsrd2058-sd JobId 210: Sending spooled attrs to the Director. Despooling 309 bytes ...&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Bareos apsrd2058-dir 13.2.2 (12Nov13):&lt;BR /&gt;
  Build OS:               x86_64-unknown-linux-gnu redhat Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  JobId:                  210&lt;BR /&gt;
  Job:                    DBSRP0154-mySql-system-catalogs.2014-07-01_22.05.00_27&lt;BR /&gt;
  Backup Level:           Full&lt;BR /&gt;
  Client:                 "dbsrp0154-fd" 5.0.3 (04Aug10) x86_64-koji-linux-gnu,redhat,&lt;BR /&gt;
  FileSet:                "mysql system catalog set" 2014-06-25 22:05:04&lt;BR /&gt;
  Pool:                   "File" (From Job resource)&lt;BR /&gt;
  Catalog:                "MyCatalog" (From Client resource)&lt;BR /&gt;
  Storage:                "File3" (From Job resource)&lt;BR /&gt;
  Scheduled time:         01-Jul-2014 22:05:00&lt;BR /&gt;
  Start time:             01-Jul-2014 22:08:03&lt;BR /&gt;
  End time:               01-Jul-2014 22:08:04&lt;BR /&gt;
  Elapsed time:           1 sec&lt;BR /&gt;
  Priority:               10&lt;BR /&gt;
  FD Files Written:       1&lt;BR /&gt;
  SD Files Written:       1&lt;BR /&gt;
  FD Bytes Written:       119,761 (119.7 KB)&lt;BR /&gt;
  SD Bytes Written:       119,964 (119.9 KB)&lt;BR /&gt;
  Rate:                   119.8 KB/s&lt;BR /&gt;
  Software Compression:   None&lt;BR /&gt;
  VSS:                    no&lt;BR /&gt;
  Encryption:             no&lt;BR /&gt;
  Accurate:               no&lt;BR /&gt;
  Volume name(s):         OPV0037&lt;BR /&gt;
  Volume Session Id:      71&lt;BR /&gt;
  Volume Session Time:    1403751883&lt;BR /&gt;
  Last Volume Bytes:      890,732,465 (890.7 MB)&lt;BR /&gt;
  Non-fatal FD errors:    0&lt;BR /&gt;
  SD Errors:              0&lt;BR /&gt;
  FD termination status:  OK&lt;BR /&gt;
  SD termination status:  OK&lt;BR /&gt;
  Termination:            Backup OK&lt;/P&gt;

&lt;P&gt;01-Jul 22:08 apsrd2058-dir JobId 210: Begin pruning Jobs older than 1 month .&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: No Jobs found to prune.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: Begin pruning Files.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: No Files found to prune.&lt;BR /&gt;
01-Jul 22:08 apsrd2058-dir JobId 210: End auto prune.&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: shell command: run BeforeJob "/etc/bareos/make_catalog_backup_uhg.pl MyCatalog"&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Start Backup JobId 211, Job=BackupCatalog.2014-07-01_23.10.00_28&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Using Device "FileChgr3-Dev1" to write.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Volume "OPV0037" previously written, moving to end of data.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Ready to append to end of Volume "OPV0037" size=890732465&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Elapsed time=00:00:01, Transfer rate=25.14 M Bytes/second&lt;BR /&gt;
01-Jul 23:10 apsrd2058-sd JobId 211: Sending spooled attrs to the Director. Despooling 293 bytes ...&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Bareos apsrd2058-dir 13.2.2 (12Nov13):&lt;BR /&gt;
  Build OS:               x86_64-unknown-linux-gnu redhat Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  JobId:                  211&lt;BR /&gt;
  Job:                    BackupCatalog.2014-07-01_23.10.00_28&lt;BR /&gt;
  Backup Level:           Full&lt;BR /&gt;
  Client:                 "apsrd2058-fd" 13.2.2 (12Nov13) x86_64-unknown-linux-gnu,redhat,Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  FileSet:                "Catalog" 2014-06-25 22:25:22&lt;BR /&gt;
  Pool:                   "File" (From Job resource)&lt;BR /&gt;
  Catalog:                "MyCatalog" (From Client resource)&lt;BR /&gt;
  Storage:                "File3" (From Job resource)&lt;BR /&gt;
  Scheduled time:         01-Jul-2014 23:10:00&lt;BR /&gt;
  Start time:             01-Jul-2014 23:10:03&lt;BR /&gt;
  End time:               01-Jul-2014 23:10:04&lt;BR /&gt;
  Elapsed time:           1 sec&lt;BR /&gt;
  Priority:               11&lt;BR /&gt;
  FD Files Written:       1&lt;BR /&gt;
  SD Files Written:       1&lt;BR /&gt;
  FD Bytes Written:       25,146,795 (25.14 MB)&lt;BR /&gt;
  SD Bytes Written:       25,146,914 (25.14 MB)&lt;BR /&gt;
  Rate:                   25146.8 KB/s&lt;BR /&gt;
  Software Compression:   None&lt;BR /&gt;
  VSS:                    no&lt;BR /&gt;
  Encryption:             no&lt;BR /&gt;
  Accurate:               no&lt;BR /&gt;
  Volume name(s):         OPV0037&lt;BR /&gt;
  Volume Session Id:      72&lt;BR /&gt;
  Volume Session Time:    1403751883&lt;BR /&gt;
  Last Volume Bytes:      915,898,455 (915.8 MB)&lt;BR /&gt;
  Non-fatal FD errors:    0&lt;BR /&gt;
  SD Errors:              0&lt;BR /&gt;
  FD termination status:  OK&lt;BR /&gt;
  SD termination status:  OK&lt;BR /&gt;
  Termination:            Backup OK&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: Begin pruning Jobs older than 2 months .&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: No Jobs found to prune.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Begin pruning Files.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: Pruned Files from 1 Jobs for client apsrd2058-fd from catalog.&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: End auto prune.&lt;/P&gt;

&lt;P&gt;01-Jul 23:10 apsrd2058-dir JobId 211: shell command: run AfterJob "/etc/bareos/delete_catalog_backup_uhg"&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + db_name=BUAASbareos&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + wd=/var/lib/bareos&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + max_versions=5&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + max_days=7&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: ++ find /var/lib/bareos -name '*BUAASbareos*sql'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: ++ wc -l&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: find: failed to restore initial working directory: Permission denied&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + filecount=11&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + echo 'filecount = 11'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: filecount = 11&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + '[' 11 -gt 5 ']'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + find /var/lib/bareos -name '*BUAASbareos*sql' -ctime +7 -exec rm -f '{}' ';'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: find: failed to restore initial working directory: Permission denied&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + '[' -f /var/lib/bareos/BUAASbareos.sql ']'&lt;BR /&gt;
01-Jul 23:10 apsrd2058-dir JobId 211: AfterJob: + rm -f /var/lib/bareos/BUAASbareos.sql&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Start Backup JobId 212, Job=DBSED1397-SqlServer.2014-07-02_21.10.00_29&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Using Device "FileChgr3-Dev1" to write.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Volume "OPV0037" previously written, moving to end of data.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Ready to append to end of Volume "OPV0037" size=915898455&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: Generate VSS snapshots. Driver="Win64 VSS", Drive(s)="E"&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Task Scheduler Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "VSS Metadata Store Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Performance Counters Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "System Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "SqlServerWriter", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "ASR Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Shadow Copy Optimization Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "Registry Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "BITS Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "COM+ REGDB Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 dbsed1397-fd JobId 212: VSS Writer (BackupComplete): "WMI Writer", State: 0x1 (VSS_WS_STABLE)&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Elapsed time=00:00:13, Transfer rate=34.21 K Bytes/second&lt;BR /&gt;
02-Jul 21:10 apsrd2058-sd JobId 212: Sending spooled attrs to the Director. Despooling 1,130 bytes ...&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Bareos apsrd2058-dir 13.2.2 (12Nov13):&lt;BR /&gt;
  Build OS:               x86_64-unknown-linux-gnu redhat Red Hat Enterprise Linux Server release 6.3 (Santiago)&lt;BR /&gt;
  JobId:                  212&lt;BR /&gt;
  Job:                    DBSED1397-SqlServer.2014-07-02_21.10.00_29&lt;BR /&gt;
  Backup Level:           Full&lt;BR /&gt;
  Client:                 "dbsed1397-fd" 5.2.10 (28Jun12) Microsoft Windows Server 2008 R2 Enterprise Edition Service Pack 1 (build 7601), 64-bit,Cross-compile,Win64&lt;BR /&gt;
  FileSet:                "SQL Server Set" 2014-06-25 21:36:10&lt;BR /&gt;
  Pool:                   "File" (From Job resource)&lt;BR /&gt;
  Catalog:                "MyCatalog" (From Client resource)&lt;BR /&gt;
  Storage:                "File3" (From Job resource)&lt;BR /&gt;
  Scheduled time:         02-Jul-2014 21:10:00&lt;BR /&gt;
  Start time:             02-Jul-2014 21:10:03&lt;BR /&gt;
  End time:               02-Jul-2014 21:10:17&lt;BR /&gt;
  Elapsed time:           14 secs&lt;BR /&gt;
  Priority:               10&lt;BR /&gt;
  FD Files Written:       3&lt;BR /&gt;
  SD Files Written:       3&lt;BR /&gt;
  FD Bytes Written:       443,984 (443.9 KB)&lt;BR /&gt;
  SD Bytes Written:       444,742 (444.7 KB)&lt;BR /&gt;
  Rate:                   31.7 KB/s&lt;BR /&gt;
  Software Compression:   85.7 % (gzip)&lt;BR /&gt;
  VSS:                    yes&lt;BR /&gt;
  Encryption:             no&lt;BR /&gt;
  Accurate:               no&lt;BR /&gt;
  Volume name(s):         OPV0037&lt;BR /&gt;
  Volume Session Id:      73&lt;BR /&gt;
  Volume Session Time:    1403751883&lt;BR /&gt;
  Last Volume Bytes:      916,344,491 (916.3 MB)&lt;BR /&gt;
  Non-fatal FD errors:    0&lt;BR /&gt;
  SD Errors:              0&lt;BR /&gt;
  FD termination status:  OK&lt;BR /&gt;
  SD termination status:  OK&lt;BR /&gt;
  Termination:            Backup OK&lt;/P&gt;

&lt;P&gt;02-Jul 21:10 apsrd2058-dir JobId 212: Begin pruning Jobs older than 12 months .&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: No Jobs found to prune.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: Begin pruning Files.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: No Files found to prune.&lt;BR /&gt;
02-Jul 21:10 apsrd2058-dir JobId 212: End auto prune.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-line-breaks-for-multiline-events/m-p/127567#M26215</guid>
      <dc:creator>paqua77</dc:creator>
      <dc:date>2020-09-28T17:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure line breaks for multiline events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-line-breaks-for-multiline-events/m-p/127568#M26216</link>
      <description>&lt;P&gt;Props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;BREAK_ONLY_BEFORE=^\d+\-\w+\s\d{2}\:\d{2}
MAX_TIMESTAMP_LOOKAHEAD=150
NO_BINARY_CHECK=1
SHOULD_LINEMERGE=true
TIME_FORMAT=%d-%b %H:%M
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then, append this to your search to setup a transaction (what you actually should be doing)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rex field=_raw "JobId\s(?&amp;lt;job_id&amp;gt;\d+)" | sort + _time | transaction job_id
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 22 Sep 2014 21:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-line-breaks-for-multiline-events/m-p/127568#M26216</guid>
      <dc:creator>ShaneNewman</dc:creator>
      <dc:date>2014-09-22T21:38:19Z</dc:date>
    </item>
  </channel>
</rss>

