<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to split a log file which contain multiple KPI information as many individual events  using the delimiter &amp;quot;===========&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345256#M63451</link>
    <description>&lt;P&gt;[Pra] KPI_DB_001: Transactions per sec&lt;/P&gt;

&lt;P&gt;Detailed breakdown of processing time                    %                 Total&lt;BR /&gt;&lt;BR /&gt;
                                                                                      ***********************************************&lt;BR /&gt;
  Total processing                                                          100               14566023932               &lt;/P&gt;

&lt;P&gt;Section execution&lt;BR /&gt;&lt;BR /&gt;
    TOTAL_SECTION_PROC_TIME                                       3                 575697340                 &lt;/P&gt;

&lt;H1&gt;      TOTAL_SECTION_SORT_PROC_TIME                          0                 3809                     &lt;/H1&gt;

&lt;P&gt;[Pra] KPI_DB_005 Buffer pool hit ratio.                                          &lt;/P&gt;

&lt;P&gt;Type             Ratio                      Formula                                       &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Data             9                             (1-(16829502+6813417-15031035)/(3417808829+576&lt;BR /&gt;
  Index            99                          (1-(4308509+1968-191493)/(6726500833+356522)) &lt;/P&gt;

&lt;P&gt;================================================================================                                                                                                         &lt;/P&gt;

&lt;P&gt;[Pra] KPI_DB_007                      &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Per activity                    Total                                      (micro sec or nano sec ?)                  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;LOCK_WAIT_TIME          0                                                   2131581&lt;BR /&gt;&lt;BR /&gt;
  LOCK_WAITS                   0                                                   547                     &lt;/P&gt;

&lt;P&gt;================================================================================&lt;/P&gt;

&lt;P&gt;[Pra] KPI_DB_006           &lt;/P&gt;

&lt;P&gt;Row processing &lt;BR /&gt;
    ROWS_READ/ROWS_RETURNED         = 3325 (292223944055/87871120)&lt;/P&gt;

&lt;P&gt;================================================================================&lt;/P&gt;

&lt;P&gt;i want each kpi as individual event while importing my log file, please help me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:50:21 GMT</pubDate>
    <dc:creator>senthamilselvan</dc:creator>
    <dc:date>2020-09-29T15:50:21Z</dc:date>
    <item>
      <title>how to split a log file which contain multiple KPI information as many individual events  using the delimiter "==========="?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345256#M63451</link>
      <description>&lt;P&gt;[Pra] KPI_DB_001: Transactions per sec&lt;/P&gt;

&lt;P&gt;Detailed breakdown of processing time                    %                 Total&lt;BR /&gt;&lt;BR /&gt;
                                                                                      ***********************************************&lt;BR /&gt;
  Total processing                                                          100               14566023932               &lt;/P&gt;

&lt;P&gt;Section execution&lt;BR /&gt;&lt;BR /&gt;
    TOTAL_SECTION_PROC_TIME                                       3                 575697340                 &lt;/P&gt;

&lt;H1&gt;      TOTAL_SECTION_SORT_PROC_TIME                          0                 3809                     &lt;/H1&gt;

&lt;P&gt;[Pra] KPI_DB_005 Buffer pool hit ratio.                                          &lt;/P&gt;

&lt;P&gt;Type             Ratio                      Formula                                       &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Data             9                             (1-(16829502+6813417-15031035)/(3417808829+576&lt;BR /&gt;
  Index            99                          (1-(4308509+1968-191493)/(6726500833+356522)) &lt;/P&gt;

&lt;P&gt;================================================================================                                                                                                         &lt;/P&gt;

&lt;P&gt;[Pra] KPI_DB_007                      &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Per activity                    Total                                      (micro sec or nano sec ?)                  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;LOCK_WAIT_TIME          0                                                   2131581&lt;BR /&gt;&lt;BR /&gt;
  LOCK_WAITS                   0                                                   547                     &lt;/P&gt;

&lt;P&gt;================================================================================&lt;/P&gt;

&lt;P&gt;[Pra] KPI_DB_006           &lt;/P&gt;

&lt;P&gt;Row processing &lt;BR /&gt;
    ROWS_READ/ROWS_RETURNED         = 3325 (292223944055/87871120)&lt;/P&gt;

&lt;P&gt;================================================================================&lt;/P&gt;

&lt;P&gt;i want each kpi as individual event while importing my log file, please help me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:50:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345256#M63451</guid>
      <dc:creator>senthamilselvan</dc:creator>
      <dc:date>2020-09-29T15:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: how to split a log file which contain multiple KPI information as many individual events  using the delimiter "==========="?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345257#M63452</link>
      <description>&lt;P&gt;HI senthamilselvanj,&lt;BR /&gt;
did you tried to insert in your props.conf something like the following configuration?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ your_sourcetype]
SHOULD_LINEMERGE=true
NO_BINARY_CHECK=true
BREAK_ONLY_BEFORE=\[Pra\]\s+KPI
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 15:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345257#M63452</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-21T15:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: how to split a log file which contain multiple KPI information as many individual events  using the delimiter "==========="?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345258#M63453</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;Thank you for the replay, I tried but the syntax is not working as expected. Please find the below detailed info.&lt;BR /&gt;
The below is my sample log files. All the information will come as single log file and i want to breaks this as separate events based on the delimiter "=====" . which is coming along with the log file. &lt;/P&gt;

&lt;H2&gt;Monitoring report - database summary&lt;/H2&gt;

&lt;P&gt;Database:                                 DQA01CDW&lt;BR /&gt;&lt;BR /&gt;
  Generated:                                08/16/2017 11:03:38                   &lt;/P&gt;

&lt;H1&gt;  Interval monitored:                       900 &lt;/H1&gt;

&lt;P&gt;Transactions per sec&lt;BR /&gt;
  ACT_COMPLETED_TOTAL               2760&lt;A href="https://community.splunk.com/TPS%20Value" target="_blank"&gt;Pra&lt;/A&gt;                   2484587[Pra]  TPS cumulative value for last 900 sec &lt;/P&gt;

&lt;H1&gt;  Component times      &lt;/H1&gt;

&lt;P&gt;-- Detailed breakdown of processing time --                                     &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;                                  %                 Total                     
                                  ----------------  --------------------------
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;H1&gt;  Total processing                    100               14566023932             &lt;/H1&gt;

&lt;P&gt;Buffer pool hit ratio. This KPI is captured based on type, we can include Data, Index, XDA, COL. Formula is nice to have&lt;BR /&gt;
  Buffer pool                                                                     &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Buffer pool hit ratios                 &lt;/P&gt;

&lt;P&gt;Type             Ratio            Formula                                       &lt;/P&gt;

&lt;HR /&gt;

&lt;H1&gt;  Data             9&lt;A href="https://community.splunk.com/Value" target="_blank"&gt;Pra&lt;/A&gt;   (1-(16829502+6813417-15031035)/(3417808829+576           &lt;/H1&gt;

&lt;P&gt;I tried using the below props.config file to split the logs&lt;BR /&gt;
[dbmonitoring]&lt;BR /&gt;
BREAK_ONLY_BEFORE = [=]+&lt;BR /&gt;
DATETIME_CONFIG = CURRENT&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
category = Application&lt;BR /&gt;
pulldown_type = true&lt;/P&gt;

&lt;P&gt;But still events are not separated as expected based on delimiter. &lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
selvan&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-to-split-a-log-file-which-contain-multiple-KPI-information/m-p/345258#M63453</guid>
      <dc:creator>senthamilselvan</dc:creator>
      <dc:date>2020-09-29T15:50:29Z</dc:date>
    </item>
  </channel>
</rss>

