<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Break event and extract fields from script input in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Break-event-and-extract-fields-from-script-input/m-p/373164#M67640</link>
    <description>&lt;P&gt;Hey, check these answers, they should be adaptable to your problem:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/170826/set-delimiter.html"&gt;https://answers.splunk.com/answers/170826/set-delimiter.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/627420/how-do-i-load-the-custom-delimited-file-with-heade.html"&gt;https://answers.splunk.com/answers/627420/how-do-i-load-the-custom-delimited-file-with-heade.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 May 2018 08:34:00 GMT</pubDate>
    <dc:creator>xpac</dc:creator>
    <dc:date>2018-05-02T08:34:00Z</dc:date>
    <item>
      <title>Break event and extract fields from script input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Break-event-and-extract-fields-from-script-input/m-p/373163#M67639</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Am getting custom scripted input from one of our app server, but wanted to know understand how to break these events and extract fields for below sample output. Could you please help me to solve this.&lt;/P&gt;

&lt;P&gt;Suffix DN         : Server                  : Entries : Replication enabled : DS ID : RS ID : RS Port (1) : M.C. (2) : A.O.M.C. (3) : Security (4)&lt;BR /&gt;
dc=domain,dc=com  : server1.domain.com:PORT : 156827  : true                : 23636 : 11208 : 8989        : 0        :              : true&lt;BR /&gt;
dc=domain,dc=com  : server2.domain.com:PORT : 156827  : true                : 14162 : 7315  : 8989        : 0        :              : true&lt;BR /&gt;
Suffix DN         : Server                  : Entries : Replication enabled : DS ID : RS ID : RS Port (1) : M.C. (2) : A.O.M.C. (3) : Security (4)&lt;BR /&gt;
dc=domain,dc=com  : server1.domain.com:PORT : 156827  : true                : 23636 : 11208 : 8989        : 0        :              : true&lt;BR /&gt;
dc=domain,dc=com  : server2.domain.com:PORT : 156827  : true                : 14162 : 7315  : 8989        : 0        :              : true&lt;BR /&gt;
Suffix DN         : Server                  : Entries : Replication enabled : DS ID : RS ID : RS Port (1) : M.C. (2) : A.O.M.C. (3) : Security (4)&lt;BR /&gt;
dc=domain,dc=com  : server1.domain.com:PORT : 156827  : true                : 23636 : 11208 : 8989        : 0        :              : true&lt;BR /&gt;
dc=domain,dc=com  : server2.domain.com:PORT : 156827  : true                : 14162 : 7315  : 8989        : 0        :              : true&lt;/P&gt;

&lt;P&gt;Thanks!&lt;BR /&gt;
Pavan&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 08:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Break-event-and-extract-fields-from-script-input/m-p/373163#M67639</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2018-05-02T08:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Break event and extract fields from script input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Break-event-and-extract-fields-from-script-input/m-p/373164#M67640</link>
      <description>&lt;P&gt;Hey, check these answers, they should be adaptable to your problem:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/170826/set-delimiter.html"&gt;https://answers.splunk.com/answers/170826/set-delimiter.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/627420/how-do-i-load-the-custom-delimited-file-with-heade.html"&gt;https://answers.splunk.com/answers/627420/how-do-i-load-the-custom-delimited-file-with-heade.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 08:34:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Break-event-and-extract-fields-from-script-input/m-p/373164#M67640</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-02T08:34:00Z</dc:date>
    </item>
  </channel>
</rss>

