<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set up props.conf so that each source is a single event in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131464#M27026</link>
    <description>&lt;P&gt;Could you post a few samples? And also, indicate &lt;BR /&gt;
at what points the file is currently being broken.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2014 16:32:22 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2014-01-30T16:32:22Z</dc:date>
    <item>
      <title>How to set up props.conf so that each source is a single event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131463#M27025</link>
      <description>&lt;P&gt;Currently we are monitoring a directory with batch jobs logs in it and it is not breaking correctly. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///home/prod/department/interface/joblogs/*]
sourcetype = joblogs
index = finance
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I am trying to break the files up here.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[joblogs]
BREAK_ONLY_BEFORE = (E r r o r\s+L o g|J o b\s+L o g)
NO_BINARY_CHECK=1
SHOULD_LINEMERGE = True
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We are setting the source to the log file name so each different file has a unique source name.  I do not want to change the sourcetype name or split the sourcetypes by file.  Ideally I am looking to break each file into one event based on the source so that each different file would be 1 event within the index.  It is currently breaking the logs into several events. &lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 14:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131463#M27025</guid>
      <dc:creator>mux</dc:creator>
      <dc:date>2014-01-30T14:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up props.conf so that each source is a single event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131464#M27026</link>
      <description>&lt;P&gt;Could you post a few samples? And also, indicate &lt;BR /&gt;
at what points the file is currently being broken.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 16:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131464#M27026</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-01-30T16:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up props.conf so that each source is a single event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131465#M27027</link>
      <description>&lt;P&gt;Does the word "Error Log" really have spaces between every letter like that?  Literally "&lt;CODE&gt;E r r o r  L o g&lt;/CODE&gt;" or is it possible that you have some kind of character set issue?  (like UTF-16 or something).  That's a long-shot, but it may be relevant.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 16:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131465#M27027</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2014-01-30T16:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up props.conf so that each source is a single event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131466#M27028</link>
      <description>&lt;P&gt;No problem, do this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[joblogs]
NO_BINARY_CHECK=1
SHOULD_LINEMERGE = false
LINE_BREAKER = ((*FAIL))
TRUNCATE = 99999999
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I used this &lt;A href="http://answers.splunk.com/answers/106075/each-file-as-one-single-splunk-event"&gt;answer&lt;/A&gt; for the info.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 16:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131466#M27028</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-01-30T16:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up props.conf so that each source is a single event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131467#M27029</link>
      <description>&lt;P&gt;Thank you I believe this will do the trick, I will double check in the AM after the batch jobs have run tonight.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 17:12:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-props-conf-so-that-each-source-is-a-single-event/m-p/131467#M27029</guid>
      <dc:creator>mux</dc:creator>
      <dc:date>2014-01-30T17:12:57Z</dc:date>
    </item>
  </channel>
</rss>

