<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: line-break issues in events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298024#M56400</link>
    <description>&lt;P&gt;I gave a try again with &lt;CODE&gt;LINE_BREAKER = ([\r\n]+)&lt;/CODE&gt; and It worked fine on version 6.5.3&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2017 08:00:36 GMT</pubDate>
    <dc:creator>aakwah</dc:creator>
    <dc:date>2017-05-19T08:00:36Z</dc:date>
    <item>
      <title>line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298021#M56397</link>
      <description>&lt;P&gt;I'm having issues with line break for some reason.  I'm looking to break into individual line events.  I've included the following in the specific apps props.conf.  Any suggestions? &lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[SPLUNK_INCL_DATA.DAT]&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
LINE_BREAKER = ([\r\n]+)&lt;/P&gt;

&lt;P&gt;raw data&lt;BR /&gt;
y8200|ACH-NEW-R|05/16/2017|7|1|5|881.24|3|50.24|INC_ACH-NEW-R3-0516.PBS|05/16/2017|2|397| &lt;BR /&gt;
y8200|ACH-NEW-R|05/16/2017|8|1|0|0.00|1|412.00|INC_ACH-NEW-R4-0516.PBS|05/16/2017||| &lt;BR /&gt;
y8200|ACH-R|05/16/2017|1|1|27332|19348046.77|11142|10812534.28|INC_ACH-R1-0516.PBS|05/16/2017|5|33| &lt;BR /&gt;
y8200|ACH-R|05/16/2017|2|1|43093|106558388.19|40396|117051987.96|INC_ACH-R2-0516.PBS|05/16/2017||| &lt;BR /&gt;
y8200|ACH-R|05/16/2017|3|1|14949|6935959.69|5846|5575650.96|INC_ACH-R3-0516.PBS|05/16/2017||0| &lt;BR /&gt;
y8200|ACH-R|05/16/2017|4|1|11145|2342435.86|4304|5653510.66|INC_ACH-R4-0516.PBS|05/16/2017|||&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298021#M56397</guid>
      <dc:creator>fisuser1</dc:creator>
      <dc:date>2020-09-29T14:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298022#M56398</link>
      <description>&lt;P&gt;You need to:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Make sure that the sourcetype in the stanza header matches EXACTLY the sourcetype of your data.&lt;/LI&gt;
&lt;LI&gt;Deploy this to each of your indexers&lt;/LI&gt;
&lt;LI&gt;Restart splunk on each indexer&lt;/LI&gt;
&lt;LI&gt;Test by searching ONLY against data indexed AFTER the deploy/restart (old data will stay broken)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 May 2017 12:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298022#M56398</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-05-17T12:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298023#M56399</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;According to docs what you are doing should work fine, however it doesn't work for me as well.&lt;/P&gt;

&lt;P&gt;For sample logs you have provided, the following worked fine:&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[SPLUNK_INCL_DATA.DAT]&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
BREAK_ONLY_BEFORE = ($)&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298023#M56399</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2020-09-29T14:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298024#M56400</link>
      <description>&lt;P&gt;I gave a try again with &lt;CODE&gt;LINE_BREAKER = ([\r\n]+)&lt;/CODE&gt; and It worked fine on version 6.5.3&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 08:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298024#M56400</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2017-05-19T08:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298025#M56401</link>
      <description>&lt;P&gt;working fine, But how.? could you please explain.?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 13:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298025#M56401</guid>
      <dc:creator>gvnd</dc:creator>
      <dc:date>2017-05-19T13:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298026#M56402</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
$ matches the end of the line, it is working the same like ^ with start of the line &lt;BR /&gt;
Regards&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 14:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298026#M56402</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2017-05-19T14:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298027#M56403</link>
      <description>&lt;P&gt;Hi , &lt;BR /&gt;
1- Where is props.conf stored &amp;amp; let me know this change will impact all logs or specific log . &lt;BR /&gt;
2- Can I enforce splunk to monitor log line by line using input.conf &lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 23:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298027#M56403</guid>
      <dc:creator>khalidewaidah</dc:creator>
      <dc:date>2017-06-30T23:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: line-break issues in events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298028#M56404</link>
      <description>&lt;P&gt;props.conf file location : $SPLUNK_HOME/etc/system/local&lt;BR /&gt;
Inside the directory you find props.conf,in case if you don't have create new one with props.conf name.&lt;BR /&gt;
Place that code inside file after restart the splunkd service.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 23:24:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/line-break-issues-in-events/m-p/298028#M56404</guid>
      <dc:creator>prathapkcsc</dc:creator>
      <dc:date>2017-06-30T23:24:15Z</dc:date>
    </item>
  </channel>
</rss>

