<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to break my events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355210#M64946</link>
    <description>&lt;P&gt;Thanks @somesoni2.&lt;BR /&gt;
It worked but the end of the event is looking as &amp;lt; instead of &lt;/P&gt;

&lt;P&gt;&lt;I&gt;PDT Socket Created&lt;/I&gt;&lt;B&gt;642949672951&lt;/B&gt;&amp;lt;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2017 19:20:53 GMT</pubDate>
    <dc:creator>chintan_shah</dc:creator>
    <dc:date>2017-04-28T19:20:53Z</dc:date>
    <item>
      <title>How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355205#M64941</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
i am trying to break the event which we receive from our hand held devices into separate events but its not working properly.&lt;BR /&gt;
The logs doesn't have any LINE BREAKER and i am using /msg&amp;gt; as delimiter but its not working.&lt;BR /&gt;
Can some one help me in breaking this event?&lt;/P&gt;

&lt;P&gt;Sample Logs:&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 16:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355205#M64941</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-04-28T16:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355206#M64942</link>
      <description>&lt;P&gt;You're missing sample logs here.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 16:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355206#M64942</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-28T16:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355207#M64943</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Please find the sample log&lt;BR /&gt;
&lt;I&gt;PDT Socket Created&lt;/I&gt;&lt;B&gt;2214294967295&lt;/B&gt;&lt;I&gt;Extracted PDT Request&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 18:38:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355207#M64943</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-04-28T18:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355208#M64944</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg t='status' e='2' d='2017/04/28 14:31:28'&amp;gt;&amp;lt;s f='' h='CPDTSocket()'/&amp;gt;&amp;lt;i&amp;gt;PDT Socket Created&amp;lt;/i&amp;gt;&amp;lt;b&amp;gt;&amp;lt;z&amp;gt;&amp;lt;v n='PDTSocket ID'&amp;gt;221&amp;lt;/v&amp;gt;&amp;lt;/z&amp;gt;&amp;lt;z&amp;gt;&amp;lt;v n='Socket Handle'&amp;gt;4294967295&amp;lt;/v&amp;gt;&amp;lt;/z&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;/msg&amp;gt;&amp;lt;msg t='status' e='2' d='2017/04/28 14:31:28'&amp;gt;&amp;lt;s f='' h='FetchRequest()'/&amp;gt;&amp;lt;i&amp;gt;Extracted PDT Request&amp;lt;/i&amp;gt;&amp;lt;/msg&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Apr 2017 18:41:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355208#M64944</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-04-28T18:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355209#M64945</link>
      <description>&lt;P&gt;Try this for your line breaking configuration&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\&amp;gt;)*(?=\&amp;lt;msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Apr 2017 18:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355209#M64945</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-28T18:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355210#M64946</link>
      <description>&lt;P&gt;Thanks @somesoni2.&lt;BR /&gt;
It worked but the end of the event is looking as &amp;lt; instead of &lt;/P&gt;

&lt;P&gt;&lt;I&gt;PDT Socket Created&lt;/I&gt;&lt;B&gt;642949672951&lt;/B&gt;&amp;lt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 19:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355210#M64946</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-04-28T19:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355211#M64947</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;msg t='status' e='2' d='2017/03/30 09:41:05'&amp;gt;&amp;lt;s f='' h='CPDTSocket()'/&amp;gt;&amp;lt;i&amp;gt;PDT Socket Created&amp;lt;/i&amp;gt;&amp;lt;b&amp;gt;&amp;lt;z&amp;gt;&amp;lt;v n='PDTSocket ID'&amp;gt;6&amp;lt;/v&amp;gt;&amp;lt;/z&amp;gt;&amp;lt;z&amp;gt;&amp;lt;v n='Socket Handle'&amp;gt;4294967295&amp;lt;/v&amp;gt;&amp;lt;/z&amp;gt;&amp;lt;z&amp;gt;&amp;lt;v n='(logs removed)'&amp;gt;1&amp;lt;/v&amp;gt;&amp;lt;/z&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Apr 2017 19:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355211#M64947</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-04-28T19:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355212#M64948</link>
      <description>&lt;P&gt;It's actually removing string in first brackets in LINE_BREAKER. If you need that you can use below,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yoursourcetype]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=(\&amp;lt;msg)
 TIME_PREFIX=d='
 TIME_FORMAT=%Y/%m/%d %H:%M:%S
 MAX_TIMESTAMP_LOOKAHEAD=19
 SEDCMD-addheader = s/^(.+)/&amp;lt;msg \1/
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Apr 2017 19:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355212#M64948</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-28T19:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to break my events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355213#M64949</link>
      <description>&lt;P&gt;Thanks Somesoni2. It worked.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 20:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-break-my-events/m-p/355213#M64949</guid>
      <dc:creator>chintan_shah</dc:creator>
      <dc:date>2017-04-28T20:25:39Z</dc:date>
    </item>
  </channel>
</rss>

