<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BREAK_ONLY_BEFORE not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179969#M36086</link>
    <description>&lt;P&gt;Your regex should match, except there's no need to escape the 'J'.&lt;/P&gt;</description>
    <pubDate>Mon, 04 May 2015 20:13:48 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2015-05-04T20:13:48Z</dc:date>
    <item>
      <title>BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179966#M36083</link>
      <description>&lt;P&gt;I have a clustered system that I am using, and I'm attempting to break events at the search head level, and it seems right though the events aren't breaking appropriately.  I am attempting to break the event at the "Job &amp;lt;myJob&amp;gt;" portion of the messages below.  also, for whatever reason, the 'code box' on here replaces the symbol "&amp;lt;" with an ampersand, and a "lt" just as a heads up. &lt;/P&gt;

&lt;P&gt;This is an example of the log messages: &lt;BR /&gt;
    Job &amp;lt;myJob&amp;gt;, User &amp;lt;myuser&amp;gt;, Project &amp;lt;default&amp;gt;, Status &amp;lt;RUN&amp;gt;, Queue &amp;lt;normal&amp;gt;, &lt;BR /&gt;
                         Command &amp;lt;myCommand&amp;gt;&lt;BR /&gt;
    Mon Apr 27 07:33:03: Submitted from host &amp;lt;myHost&amp;gt;, CWD &amp;lt;$HOME&lt;BR /&gt;
                         &amp;gt;;&lt;BR /&gt;
    Mon Apr 27 07:33:04: Started on &amp;lt;myHost&amp;gt;, Execution Home &amp;lt;/myHome&amp;gt;, Execution CWD &amp;lt;myCwd&amp;gt;;&lt;BR /&gt;
    Tue Apr 28 09:57:59: Resource usage collected.&lt;BR /&gt;
                         The CPU time used is 1345 seconds.&lt;BR /&gt;
                         MEM: 114 Mbytes;  SWAP: 35.1 Gbytes;  NTHREAD: 54&lt;BR /&gt;
                         PGID: 9430;  PIDs: 9430 9435 9437 9450 9501 &lt;BR /&gt;
                         PGID: 9461;  PIDs: 9461 &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; MEMORY USAGE:
 MAX MEM: 4.2 Gbytes;  AVG MEM: 194 Mbytes

 SCHEDULING PARAMETERS:
           r15s   r1m  r15m   ut      pg    io   ls    it    tmp    swp    mem
 loadSched   -     -     -   0.9       -     -    -     -     -      -      -  
 loadStop    -     -     -   0.9       -     -    -     -     -      -      -  

 RESOURCE REQUIREMENT DETAILS:
 Combined: select[type == local] order[ut:mem]
 Effective: select[type == local] order[ut:mem] 
------------------------------------------------------------------------------

Job &amp;amp;lt;myJob&amp;amp;gt;, User &amp;amp;lt;myUser&amp;amp;gt;, Project &amp;amp;lt;default&amp;amp;gt;, Status &amp;amp;lt;RUN&amp;amp;gt;, Queue &amp;amp;lt;normal&amp;amp;gt;, 
                     Interactive mode, Command &amp;amp;lt;/myCommand &amp;amp;gt;
Tue Apr 28 01:42:38: Submitted from host &amp;amp;lt;myHost&amp;amp;gt;, CWD &amp;amp;lt;/myCwd;
Tue Apr 28 01:42:38: Started on &amp;amp;lt;myHost&amp;amp;gt;;
Tue Apr 28 09:58:00: Resource usage collected.
                     The CPU time used is 192 seconds.
                     MEM: 11 Mbytes;  SWAP: 1 Gbytes;  NTHREAD: 15
                     PGID: 20416;  PIDs: 20416 
                     PGID: 20425;  PIDs: 20425 20427 20442 


 MEMORY USAGE:
 MAX MEM: 11 Mbytes;  AVG MEM: 10 Mbytes

 SCHEDULING PARAMETERS:
           r15s   r1m  r15m   ut      pg    io   ls    it    tmp    swp    mem
 loadSched   -     -     -   0.9       -     -    -     -     -      -      -  
 loadStop    -     -     -   0.9       -     -    -     -     -      -      -  

 RESOURCE REQUIREMENT DETAILS:
 Combined: select[type == local] order[ut:mem]
 Effective: select[type == local] order[ut:mem] 
------------------------------------------------------------------------------

Job &amp;amp;lt;myJob&amp;amp;gt;, User &amp;amp;lt;myUser&amp;amp;gt;, Project &amp;amp;lt;default&amp;amp;gt;, Status &amp;amp;lt;RUN&amp;amp;gt;, Queue &amp;amp;lt;normal&amp;amp;gt;, I
                     nteractive mode, Command &amp;amp;lt;/myCommand&amp;amp;gt;
Tue Apr 28 02:47:25: Submitted from host &amp;amp;lt;myHost&amp;amp;gt;, CWD &amp;amp;lt;myCwd
                     &amp;amp;gt;;
Tue Apr 28 02:47:25: Started on &amp;amp;lt;myHost&amp;amp;gt;;
Tue Apr 28 09:58:26: Resource usage collected.
                     The CPU time used is 84 seconds.
                     MEM: 8 Mbytes;  SWAP: 928 Mbytes;  NTHREAD: 14
                     PGID: 25895;  PIDs: 25895 
                     PGID: 25898;  PIDs: 25898 25900 25915 


 MEMORY USAGE:
 MAX MEM: 8 Mbytes;  AVG MEM: 7 Mbytes

 SCHEDULING PARAMETERS:
           r15s   r1m  r15m   ut      pg    io   ls    it    tmp    swp    mem
 loadSched   -     -     -   0.9       -     -    -     -     -      -      -  
 loadStop    -     -     -   0.9       -     -    -     -     -      -      -  

 RESOURCE REQUIREMENT DETAILS:
 Combined: select[type == local] order[ut:mem]
 Effective: select[type == local] order[ut:mem] 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and this is the my stanza in props.conf on the search head for this sourcetype:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mySourcetype]
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE = \Job\s.\d+.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When i use regexr.com for this extraction it matches where I need to break the event, however it doesn't seem to be working here. Am I doing something wrong? &lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 18:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179966#M36083</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2015-05-04T18:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179967#M36084</link>
      <description>&lt;P&gt;Is &amp;lt;MyJob&amp;gt; literal text or a field?  What kind of field?&lt;/P&gt;

&lt;P&gt;Have you tried putting parens around the regex to create a matching group?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 20:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179967#M36084</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-05-04T20:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179968#M36085</link>
      <description>&lt;P&gt;This is literal. In the log entry this is an integer which ends up looking like.  The brackets are in the log entry as well. &lt;/P&gt;

&lt;P&gt;Job &amp;lt;89238764&amp;gt; &lt;/P&gt;

&lt;P&gt;I have not tried putting parens around it. I can give it a shot. &lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 20:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179968#M36085</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2015-05-04T20:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179969#M36086</link>
      <description>&lt;P&gt;Your regex should match, except there's no need to escape the 'J'.&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 20:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179969#M36086</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-05-04T20:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179970#M36087</link>
      <description>&lt;P&gt;I agree. I don't know if I should be putting this at the indexing tier as well though. Do you know if this needs to be there as well? &lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 20:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179970#M36087</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2015-05-04T20:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179971#M36088</link>
      <description>&lt;P&gt;Yes, you should be setting the props.conf file on your indexer(s).&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 20:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179971#M36088</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-05-04T20:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179972#M36089</link>
      <description>&lt;P&gt;I believe that would be the problem then. When i'm able to get that setting into my indexers, I will let know the results. Currently it only resides in the search heads. &lt;/P&gt;

&lt;P&gt;Thank you! &lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 22:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179972#M36089</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2015-05-04T22:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: BREAK_ONLY_BEFORE not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179973#M36090</link>
      <description>&lt;P&gt;This is due to the "BREAK_ONLY_BEFORE" being at the search head level, and not the indexing level. Thank you Rich! &lt;/P&gt;

&lt;P&gt;in order for "BREAK_ONLY_BEFORE" to work successfully, it MUST be at the indexing tier. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/BREAK-ONLY-BEFORE-not-working/m-p/179973#M36090</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2020-09-28T19:50:44Z</dc:date>
    </item>
  </channel>
</rss>

