<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is Splunk not maintaining line breaks as in the original log? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186002#M37261</link>
    <description>&lt;P&gt;splunk enterprise 6.1.1&lt;/P&gt;

&lt;P&gt;In search view on the Splunk search head web front end, as well as in table view in the email alerts, Splunk is not maintaining line breaks as in the original log.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Aug 2014 20:56:11 GMT</pubDate>
    <dc:creator>spsrasru</dc:creator>
    <dc:date>2014-08-18T20:56:11Z</dc:date>
    <item>
      <title>Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186002#M37261</link>
      <description>&lt;P&gt;splunk enterprise 6.1.1&lt;/P&gt;

&lt;P&gt;In search view on the Splunk search head web front end, as well as in table view in the email alerts, Splunk is not maintaining line breaks as in the original log.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 20:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186002#M37261</guid>
      <dc:creator>spsrasru</dc:creator>
      <dc:date>2014-08-18T20:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186003#M37262</link>
      <description>&lt;P&gt;Can you post the original log samples and also explain where Splunk is not maintaining line breaks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 21:17:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186003#M37262</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-18T21:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186004#M37263</link>
      <description>&lt;P&gt;Other users are reporting the same thing since the upgrade to 6.1:&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/138053/line-breaks-being-removed-from-raw-data-in-email-alerts-after-upgrade-to-6-1.html"&gt;http://answers.splunk.com/answers/138053/line-breaks-being-removed-from-raw-data-in-email-alerts-after-upgrade-to-6-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 16:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186004#M37263</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2014-10-14T16:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186005#M37264</link>
      <description>&lt;P&gt;@adamw the link points to this question itself.  This said, I have seen this before 6, too.  Does it have to do with overload?  I am under the impression that this tends to happen when volume is extremely high, although I do not have direct measurement.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 16:54:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186005#M37264</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2014-10-14T16:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186006#M37265</link>
      <description>&lt;P&gt;@yuanliu sorry, copy and paste fail.  Updated the link to the other question.&lt;/P&gt;

&lt;P&gt;The alert I see it on is one where the output in each _raw cell is around 20 lines.  Under 6.0 it showed the _raw field in the table with the proper line breaks, but since our 6.1 upgrade, it ignores newlines in _raw and mashes all of the log data into one text blob.&lt;/P&gt;

&lt;P&gt;It still looks properly line break'ed in the search UI.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 16:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186006#M37265</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2014-10-14T16:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186007#M37266</link>
      <description>&lt;P&gt;anyone have a solution/workaround for this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 12:49:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186007#M37266</guid>
      <dc:creator>maimonoded</dc:creator>
      <dc:date>2015-01-27T12:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk not maintaining line breaks as in the original log?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186008#M37267</link>
      <description>&lt;P&gt;Ciao,&lt;/P&gt;

&lt;P&gt;Please check my answer reported here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/494716/how-to-split-a-multi-line-raw-to-a-multivalue-with.html?childToView=733420#answer-733420"&gt;https://answers.splunk.com/answers/494716/how-to-split-a-multi-line-raw-to-a-multivalue-with.html?childToView=733420#answer-733420&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;basically you can do in this way:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search | rex max_match=0 "^(?&amp;lt;lines&amp;gt;.+)\n+" | eval raw2=mvindex(lines,0,-1) | table raw2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Edoardo&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 16:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-not-maintaining-line-breaks-as-in-the-original-log/m-p/186008#M37267</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2019-03-12T16:03:28Z</dc:date>
    </item>
  </channel>
</rss>

