<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I configure proper line breaking for my sample multiline event in Splunk 6.4? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224669#M43965</link>
    <description>&lt;P&gt;So all these lines should be part of single events? What are the other types of lines that you've?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2016 16:47:46 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-04-28T16:47:46Z</dc:date>
    <item>
      <title>How do I configure proper line breaking for my sample multiline event in Splunk 6.4?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224668#M43964</link>
      <description>&lt;P&gt;Hi...&lt;/P&gt;

&lt;P&gt;I am using a Mainframe log which has different type of events. I am only trying to split the lines of events which look like below and no other events. How can I configure this using Line_breaker. &lt;/P&gt;

&lt;P&gt;MR0000000 DCXA     15217 01:00:01.96 INTERNAL 00000090  IEE949I 01.00.01 SMF DATA SETS 929&lt;BR /&gt;
 DR                                        929 00000090            NAME      VOLSER SIZE(BLKS) %FULL  STATUS&lt;BR /&gt;
 DR                                        929 00000090          P-SYS1.MAN1 C7SP09     99630     0  ALTERNATE&lt;BR /&gt;
 DR                                        929 00000090          S-SYS1.MAN2 C7SP14     99630    33  ACTIVE&lt;BR /&gt;
 DR                                        929 00000090          S-SYS1.MAN3 C7SP20     99630     0  ALTERNATE&lt;BR /&gt;
 DR                                        929 00000090          S-SYS1.MAN4 C7SP21     99630     0  ALTERNATE&lt;BR /&gt;
 DR                                        929 00000090          S-SYS1.MAN5 C7SP78    100080     0  ALTERNATE&lt;BR /&gt;
 DR                                        929 00000090          S-SYS1.MAN6 C7SP88    100080     0  ALTERNATE&lt;BR /&gt;
 ER                                        929 00000090          S-SYS1.MAN7 C7SP89    100080     0  ALTERNATE&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 12:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224668#M43964</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-28T12:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure proper line breaking for my sample multiline event in Splunk 6.4?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224669#M43965</link>
      <description>&lt;P&gt;So all these lines should be part of single events? What are the other types of lines that you've?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 16:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224669#M43965</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-04-28T16:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure proper line breaking for my sample multiline event in Splunk 6.4?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224670#M43966</link>
      <description>&lt;P&gt;The events vary some are single line events and some are multi line events. The multi line events are of various types. &lt;/P&gt;

&lt;P&gt;In the above event the reason I want to split is because I wan to extract two fields on of the data set name and the other is percentage utilized. Since this is a single event I am not able to successfully extract this data. highlighted is the field I want to extract. &lt;/P&gt;

&lt;P&gt;ER 929 00000090 &lt;STRONG&gt;S-SYS1.MAN7&lt;/STRONG&gt; C7SP89 100080 &lt;STRONG&gt;0&lt;/STRONG&gt; ALTERNATE&lt;/P&gt;

&lt;P&gt;Example of single line event&lt;/P&gt;

&lt;P&gt;N 6000000 DCXA     15217 00:51:34.62 STC15574 00000090  GLO2106I INCREASING SECONDARY ALLOCATION TO 109  CYLS -AOPT&lt;/P&gt;

&lt;P&gt;Example of multiline event &lt;/P&gt;

&lt;P&gt;M 0020000 DCXA     15217 00:51:36.91 STC02536 00000281  SVTM052I STEP1    COPY     ARIBAGL (  59,953) SNODE=CD.VIPCD01 044&lt;BR /&gt;
 D                                         044 00000281  SVTM052I      FROM GLP0.OUT.DFS.TRECS.DLYTRN.G1086V00&lt;BR /&gt;
 D                                         044 00000281  SVTM052I      TO   /opt/cdunix/data/INT...ly_20150805005136.dat&lt;BR /&gt;
 E                                         044 00000281  SVTM052I     #### COMPLETED  00000008/SDE0210I&lt;/P&gt;

&lt;P&gt;Example of multiline event &lt;/P&gt;

&lt;P&gt;MR0000000 DCXA     15217 00:51:37.28 AUTSYSXA 00000090  IEE112I 00.51.37 PENDING REQUESTS 067&lt;BR /&gt;
 LR                                        067 00000090  RM=3    IM=0     CEM=0     EM=0     RU=0    IR=0    NOAMRF&lt;BR /&gt;
 LR                                        067 00000090  ID:R/K     T JOB ID   MESSAGE TEXT&lt;BR /&gt;
 DR                                        067 00000090          41 R C653STAT *41 IEF235D C653STAT SMFDUMP WAITING FOR&lt;BR /&gt;
 DR                                        067 00000090                        VOLUMES. TO CANCEL WAIT REPLY 'NO'&lt;BR /&gt;
 DR                                        067 00000090          67 R CNMS     *67 DSI802A H160O    REPLY WITH VALID NCCF&lt;BR /&gt;
 DR                                        067 00000090                        SYSTEM OPERATOR COMMAND&lt;BR /&gt;
 DR                                        067 00000090          24 R NETV160  *24 DSI802A H160N    REPLY WITH VALID NCCF&lt;BR /&gt;
 ER                                        067 00000090                        SYSTEM OPERATOR COMMAND&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 05:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224670#M43966</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-04-29T05:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure proper line breaking for my sample multiline event in Splunk 6.4?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224671#M43967</link>
      <description>&lt;P&gt;Firstly you can still extract all the values as a multivalued field if you want by setting &lt;CODE&gt;max_match=0&lt;/CODE&gt; if you are using the &lt;CODE&gt;rex&lt;/CODE&gt; command, or modify your fields.conf if you're doing this via a REPORT transform (see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/ConfigureSplunktoparsemulti-valuefields"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/ConfigureSplunktoparsemulti-valuefields&lt;/A&gt;) for more info.&lt;/P&gt;

&lt;P&gt;However you are rightly making the effort to break the events!&lt;/P&gt;

&lt;P&gt;You need to be very clear on what constitutes a new event. From the samples you've provided I can hazard a guess that a new event starts with either:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;A letter, a space, and a seven digit number followed by a space and the string DCXA &lt;/LI&gt;
&lt;LI&gt;Two letters and a seven digit number followed by a space and the string  DCXA&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If that's the case then you could use something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE_BREAKER = ([\n\r]+)(?=\w{2}\d{7}\sDCXA|\w\s\d{7}\sDCXA)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;There are loads of good regex websites - this is an example: &lt;A href="https://regex101.com/"&gt;https://regex101.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 12:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224671#M43967</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-04-29T12:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure proper line breaking for my sample multiline event in Splunk 6.4?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224672#M43968</link>
      <description>&lt;P&gt;So 1st I will need to stop splunk. &lt;BR /&gt;
Then update the props.conf file and then start splunk. and the data will come up in different lines. &lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 13:36:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-proper-line-breaking-for-my-sample-multiline/m-p/224672#M43968</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-05-02T13:36:38Z</dc:date>
    </item>
  </channel>
</rss>

