<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help creating a sourcetype for this data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367437#M66784</link>
    <description>&lt;P&gt;micahkemp&lt;/P&gt;

&lt;P&gt;Yes, the search was run in verbose mode. I just noticed that tone was not in the regex so you're right KV_MODE=auto must have got that field&lt;/P&gt;</description>
    <pubDate>Wed, 27 Dec 2017 23:58:37 GMT</pubDate>
    <dc:creator>roayers</dc:creator>
    <dc:date>2017-12-27T23:58:37Z</dc:date>
    <item>
      <title>Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367431#M66778</link>
      <description>&lt;P&gt;I've been trying to figure out a way to create a sourcetype and extract data like this. &lt;BR /&gt;
Can someone help?    It appears to be 3 goups.&lt;/P&gt;

&lt;P&gt;Here is the ideal break out of the fields required&lt;/P&gt;

&lt;P&gt;The first 2 lines can be ignored&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Group 1&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Conventional  - system type  the fields for this group are as follows The first word conventional is not required, a space then there are 2 empty fields then these fields,&lt;BR /&gt;
name,avoid,system_type,fl_qk,tag_number,hold,time,ana_dgc,dig_agc,dig_wait_time,dig_thr_mode,dig_thr_lvl&lt;/P&gt;

&lt;P&gt;I don't need the contents of the DQKS_Status field or its values&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Group 2&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;C-Group &lt;BR /&gt;
The first word conventional is not required, there are 2 empty fields then these fields, &lt;BR /&gt;
name,avoid,latitude,longitude, range,location_type,sys_qk&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Group 3&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;C-Freq and its values are a subset of the C-Group with these fields,&lt;BR /&gt;
name, avoid,frequency,modulation,audio,dept,service_type,attenuator,delay,alert_tone,alert_light,vol_offset,num_tag, priority&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Sample data&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;TargetModel BCDx36HP&lt;BR /&gt;&lt;BR /&gt;
FormatVersion   1.00&lt;BR /&gt;
Conventional            Ft IndianTown Gap   Off     Conventional    1   Off 0   Off Off 400 Auto    8&lt;BR /&gt;
DQKs_Status     Off On  Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off&lt;BR /&gt;
C-Group Helo's Comm Card    Off 0.000000    0.000000    0.0 Circle  1&lt;BR /&gt;
C-Freq          Harrisburg N/E  Off 118250000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          CXY Tower   Off 119500000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          ABE Approach    Off 119650000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Reading Tower   Off 119900000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          LNS Tower   Off 120900000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MUIR Ground Off 121625000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          ZER CTAF    Off 123075000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Harrisburg S/W  Off 124100000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MUIR ASOS   Off 124175000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MDT Tower   Off 124800000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MUIR Tower  Off 126200000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Harrisburg S/E  Off 126450000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Reading Approach    Off 127100000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          NTA Off 141500000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Balky   Off 142450000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          NTA Off 227300000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Balky   Off 239150000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          LNS Tower   Off 251100000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          CXY Tower   Off 257800000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MDT Tower   Off 269350000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Harrisburg N/E  Off 269450000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MUIR Ground Off 269525000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Harrisburg S/W  Off 273525000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Harrisburg S/E  Off 281525000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          MUIR Tower  Off 290500000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          HQ ZER CTAF Off 300050000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          HQ Reading App  Off 375825000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          Reading Tower   Off 375925000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          HQ ABE App  Off 376125000   AUTO        208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
Conventional            Gap Range Active    Off     Conventional    2   Off 0   Off Off 400 Auto    8&lt;BR /&gt;
DQKs_Status     Off On  On  Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off Off&lt;BR /&gt;
C-Group         Air to Air Comms    Off 0.000000    0.000000    0.0 Circle  1&lt;BR /&gt;
C-Freq               Angry  Off 139150000   AM  TONE=Srch   208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            233.4500Mhz   Off 233450000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           MD ANG A10 A/A Off 271400000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            290.5000Mhz   Off 290500000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           MD ANG A10 A/A Off 293200000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             104Th TFS    Off 354800000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Group         Miscellaneous   Off 0.000000    0.000000    0.0 Circle  2&lt;BR /&gt;
C-Freq          ANG Flight Following    On  40900000    FM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             ANG Op's On  41500000    FM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             ANG Op's On  49950000    FM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            KMUI Ground   Off 121625000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             HBG Approach SW  Off 124100000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           Cleveland VHF  Off 124325000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             KMDT Tower   On  124800000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             KMUI Tower   Off 126200000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           Muir Departure Off 126450000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            133.9700Mhz   Off 133970000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             NJ ANG Air to Air    Off 139625000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            139.7000Mhz   On  139700000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             Air to Air   Off 142300000   FM      208 Off 2   0   Off Auto    Off On  Off On&lt;BR /&gt;
C-Freq          Bollen Alternate    Off 232700000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            233.4500Mhz   Off 233450000   AM      208 Off 2   0   Off Auto    Off On  Off On&lt;BR /&gt;
C-Freq            238.4000Mhz   Off 238400000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq            239.1500Mhz   Off 239150000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             Steel A/R    Off 259400000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           MD ANG A10 A/A Off 266600000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq          NY UHF Fighters Off 269100000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           MD ANG A10 A/A Off 271400000   AM      208 Off 2   2   Off Auto    Off On  Off On&lt;BR /&gt;
C-Freq            290.5000Mhz   Off 290500000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           MD ANG A10 A/A Off 293200000   AM      208 Off 2   0   Off Auto    Off On  Off On&lt;BR /&gt;
C-Freq           Steel Tankers  Off 293700000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq             Steel A/R    Off 301600000   AM      208 Off 2   0   Off Auto    Off On  Off On&lt;BR /&gt;
C-Freq          Huntress    Off 338300000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;BR /&gt;
C-Freq           Cleveland UHF  Off 353850000   AM      208 Off 2   0   Off Auto    Off On  Off On&lt;BR /&gt;
C-Freq            362.9500Mhz   Off 362950000   AM      208 Off 2   0   Off Auto    Off On  Off Off&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367431#M66778</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2020-09-29T17:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367432#M66779</link>
      <description>&lt;P&gt;This seems to extract the fields you want, though I don't know if you need multiple lines per event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[&amp;lt;sourcetype name&amp;gt;]
SHOULD_LINEMERGE = false
EXTRACT-conventional = ^Conventional (?&amp;lt;name&amp;gt;.*) (?&amp;lt;avoid&amp;gt;[^ ]+) (?&amp;lt;system_type&amp;gt;[^ ]+) (?&amp;lt;fl_quick_key&amp;gt;[^ ]+) (?&amp;lt;tag_number&amp;gt;[^ ]+) (?&amp;lt;hold&amp;gt;[^ ]+) (?&amp;lt;time&amp;gt;[^ ]+) (?&amp;lt;ana_dgc&amp;gt;[^ ]+) (?&amp;lt;dig_agc&amp;gt;[^ ]+) (?&amp;lt;dig_wait_time&amp;gt;[^ ]+) (?&amp;lt;dig_thr_mode&amp;gt;[^ ]+) (?&amp;lt;dig_thr_lvl&amp;gt;[^ ]+)$  
EXTRACT-cgroup = ^C-GroupHelo's (?&amp;lt;name&amp;gt;.*) (?&amp;lt;avoid&amp;gt;[^ ]+) (?&amp;lt;latitude&amp;gt;[^ ]+) (?&amp;lt;longitude&amp;gt;[^ ]+) (?&amp;lt;range&amp;gt;[^ ]+) (?&amp;lt;location_type&amp;gt;[^ ]+) (?&amp;lt;sys_qk&amp;gt;[^ ]+)$
EXTRACT-cfreq = ^C-Freq (?&amp;lt;name&amp;gt;.*) (?&amp;lt;avoid&amp;gt;[^ ]+) (?&amp;lt;frequency&amp;gt;[^ ]+) (?&amp;lt;modulation&amp;gt;[^ ]+) (?&amp;lt;audio&amp;gt;[^ ]+) (?&amp;lt;dept&amp;gt;[^ ]+) (?&amp;lt;service_type&amp;gt;[^ ]+) (?&amp;lt;attenuator&amp;gt;[^ ]+) (?&amp;lt;delay&amp;gt;[^ ]+) (?&amp;lt;alert_tone&amp;gt;[^ ]+) (?&amp;lt;alert_light&amp;gt;[^ ]+) (?&amp;lt;vol_offset&amp;gt;[^ ]+) (?&amp;lt;num_tag&amp;gt;[^ ]+) (?&amp;lt;priority&amp;gt;[^ ]+)$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Dec 2017 22:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367432#M66779</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-27T22:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367433#M66780</link>
      <description>&lt;P&gt;Micahkemp,&lt;/P&gt;

&lt;P&gt;Yes&lt;BR /&gt;&lt;BR /&gt;
Group 1 - conventional would only have 1 event&lt;BR /&gt;
Group 2 - cgroup would only have 1 event &lt;BR /&gt;
Group 3 - cfreq would have multiple events&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 22:25:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367433#M66780</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2017-12-27T22:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367434#M66781</link>
      <description>&lt;P&gt;What I'm asking is if they are multiline events, and if so, could you group the lines into how you would like them to exist within each event.&lt;/P&gt;

&lt;P&gt;I'm not sure your specific grouping needs will be easily accomplished in Splunk.  The ability to group events relies on a single definition of when to break into a new event.  It may be possible with some regex, but it isn't the typical use case.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 22:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367434#M66781</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-27T22:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367435#M66782</link>
      <description>&lt;P&gt;Micahkemp,&lt;/P&gt;

&lt;P&gt;I created a props.conf file in splunk\etc\apps\search\local and pasted the code into it. I added 1 line, pulldown_type = true,  i then restarted splunk. I then used the web interface to import the file into a new test index but it only parsed out 1 field, tone. It did not parse out any of the other fields.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 23:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367435#M66782</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2017-12-27T23:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367436#M66783</link>
      <description>&lt;P&gt;Did you run the search in verbose mode?  &lt;CODE&gt;tone&lt;/CODE&gt; isn't one of the fields my regexes made available, so I wonder if your sourcetype is making use of &lt;CODE&gt;KV_MODE=auto&lt;/CODE&gt; to get that one.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 23:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367436#M66783</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-27T23:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367437#M66784</link>
      <description>&lt;P&gt;micahkemp&lt;/P&gt;

&lt;P&gt;Yes, the search was run in verbose mode. I just noticed that tone was not in the regex so you're right KV_MODE=auto must have got that field&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 23:58:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367437#M66784</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2017-12-27T23:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367438#M66785</link>
      <description>&lt;P&gt;sure&lt;/P&gt;

&lt;P&gt;ideally&lt;/P&gt;

&lt;P&gt;Group1 - Convention would contain all of those fields in 1 event&lt;BR /&gt;
      |_________&lt;BR /&gt;
              Group2 - C-Group  would contain all of those fields in 1 event&lt;BR /&gt;
                              |__________&lt;BR /&gt;
                                      Group3 - C-Freg would contain all of those fields as individual events&lt;BR /&gt;
                                           |______________________&lt;BR /&gt;
                                           |______________________&lt;BR /&gt;
                                           |______________________&lt;BR /&gt;
                                           |______________________&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 16:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367438#M66785</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2017-12-28T16:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367439#M66786</link>
      <description>&lt;P&gt;micahkemp,&lt;/P&gt;

&lt;P&gt;Let me rethink this, if you had to ingest that data how would you do it?  I'm not sure of all of the best practices regarding ingesting data.  I also thought a bout a global replace in the original source file to break up the groups.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 16:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367439#M66786</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2017-12-28T16:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367440#M66787</link>
      <description>&lt;P&gt;I think you want to keep each line as a separate event.  At reporting time you may want to group them logically (via &lt;CODE&gt;stats&lt;/CODE&gt; or other search commands).  Have you tried implementing the above configurations to see what they get you?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 18:16:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367440#M66787</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-28T18:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help creating a sourcetype for this data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367441#M66788</link>
      <description>&lt;P&gt;Yes, I agree each line should be a separate event. My data file appears to have issues, there are other fields that are not displayed unless options are selected in the program that generated the files.  Now that I believe have all of the fields, I want to focus on the field extractions then I can use the the search commands to get what I'm looking for.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 19:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-creating-a-sourcetype-for-this-data/m-p/367441#M66788</guid>
      <dc:creator>roayers</dc:creator>
      <dc:date>2017-12-28T19:28:21Z</dc:date>
    </item>
  </channel>
</rss>

