<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why won't Splunk parse my multi-line event properly? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429697#M75262</link>
    <description>&lt;P&gt;I am currently unable to parse my multi-line event properly using Splunk.&lt;BR /&gt;
Here is an example from the start of the event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="utf-16"?&amp;gt;

&amp;lt;report&amp;gt;

&amp;lt;GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings"&amp;gt;
      &amp;lt;Identifier&amp;gt;
        &amp;lt;Identifier xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;{31B2F340-016D-11D2-945F-00C04FB984F9}&amp;lt;/Identifier&amp;gt;
        &amp;lt;Domain xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;options-it.com&amp;lt;/Domain&amp;gt;
      &amp;lt;/Identifier&amp;gt;
      &amp;lt;Name&amp;gt;Default Domain Policy&amp;lt;/Name&amp;gt;
      &amp;lt;IncludeComments&amp;gt;true&amp;lt;/IncludeComments&amp;gt;
      &amp;lt;CreatedTime&amp;gt;2002-09-17T07:41:34&amp;lt;/CreatedTime&amp;gt;
      &amp;lt;ModifiedTime&amp;gt;2018-05-03T13:58:32&amp;lt;/ModifiedTime&amp;gt;
      &amp;lt;ReadTime&amp;gt;2018-07-09T04:00:36.6876121Z&amp;lt;/ReadTime&amp;gt;
      &amp;lt;SecurityDescriptor&amp;gt;
        &amp;lt;SDDL xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;O:DAG:DAD:PAI(OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;LCRPRC;;;S-1-5-21-1060284298-1275210071-1417001333-95787)(A;CI;LCRPRC;;;S-1-5-21-1060284298-1275210071-1417001333-12472)(A;CI;CCDCLCRPWPSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-95786)(A;CI;CCDCLCRPWPSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-22697)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-519)(A;;LCRPLORC;;;ED)(A;CI;LCRPLORC;;;AU)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;CIIO;CCDCLCSWRPWPDTLOSDRCWDWO;;;CO)S:AI(AU;CIIDSA;CCDCSWWPDTLOCRSDWDWO;;;WD)(AU;CIIDFA;CCDCSWWPDTCRSDWDWO;;;WD)&amp;lt;/SDDL&amp;gt;
        &amp;lt;Owner xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-512&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Domain Admins&amp;lt;/Name&amp;gt;
        &amp;lt;/Owner&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am trying to get it split the events properly, where each event starts with this line:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is the props settings im trying:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    BREAK_ONLY_BEFORE=.+GPO\sxmlns:xsd.+
    CHARSET=UTF-16LE
    SHOULD_LINEMERGE=false
    disabled=false
    TIME_FORMAT=%Y-%m-%dT%H:%M:%S
    TIME_PREFIX=.+&amp;lt;ReadTime&amp;gt;
    MAX_TIMESTAMP=18
    LINE_BREAKER=.+GPO\sxmlns:xsd.+
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 09 Jul 2018 11:45:20 GMT</pubDate>
    <dc:creator>smcdonald20</dc:creator>
    <dc:date>2018-07-09T11:45:20Z</dc:date>
    <item>
      <title>Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429697#M75262</link>
      <description>&lt;P&gt;I am currently unable to parse my multi-line event properly using Splunk.&lt;BR /&gt;
Here is an example from the start of the event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="utf-16"?&amp;gt;

&amp;lt;report&amp;gt;

&amp;lt;GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings"&amp;gt;
      &amp;lt;Identifier&amp;gt;
        &amp;lt;Identifier xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;{31B2F340-016D-11D2-945F-00C04FB984F9}&amp;lt;/Identifier&amp;gt;
        &amp;lt;Domain xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;options-it.com&amp;lt;/Domain&amp;gt;
      &amp;lt;/Identifier&amp;gt;
      &amp;lt;Name&amp;gt;Default Domain Policy&amp;lt;/Name&amp;gt;
      &amp;lt;IncludeComments&amp;gt;true&amp;lt;/IncludeComments&amp;gt;
      &amp;lt;CreatedTime&amp;gt;2002-09-17T07:41:34&amp;lt;/CreatedTime&amp;gt;
      &amp;lt;ModifiedTime&amp;gt;2018-05-03T13:58:32&amp;lt;/ModifiedTime&amp;gt;
      &amp;lt;ReadTime&amp;gt;2018-07-09T04:00:36.6876121Z&amp;lt;/ReadTime&amp;gt;
      &amp;lt;SecurityDescriptor&amp;gt;
        &amp;lt;SDDL xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;O:DAG:DAD:PAI(OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;LCRPRC;;;S-1-5-21-1060284298-1275210071-1417001333-95787)(A;CI;LCRPRC;;;S-1-5-21-1060284298-1275210071-1417001333-12472)(A;CI;CCDCLCRPWPSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-95786)(A;CI;CCDCLCRPWPSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-22697)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-519)(A;;LCRPLORC;;;ED)(A;CI;LCRPLORC;;;AU)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;CIIO;CCDCLCSWRPWPDTLOSDRCWDWO;;;CO)S:AI(AU;CIIDSA;CCDCSWWPDTLOCRSDWDWO;;;WD)(AU;CIIDFA;CCDCSWWPDTCRSDWDWO;;;WD)&amp;lt;/SDDL&amp;gt;
        &amp;lt;Owner xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-512&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Domain Admins&amp;lt;/Name&amp;gt;
        &amp;lt;/Owner&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am trying to get it split the events properly, where each event starts with this line:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings"&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is the props settings im trying:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    BREAK_ONLY_BEFORE=.+GPO\sxmlns:xsd.+
    CHARSET=UTF-16LE
    SHOULD_LINEMERGE=false
    disabled=false
    TIME_FORMAT=%Y-%m-%dT%H:%M:%S
    TIME_PREFIX=.+&amp;lt;ReadTime&amp;gt;
    MAX_TIMESTAMP=18
    LINE_BREAKER=.+GPO\sxmlns:xsd.+
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 09 Jul 2018 11:45:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429697#M75262</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2018-07-09T11:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429698#M75263</link>
      <description>&lt;P&gt;Please put your example start line also as code, otherwise it disappears due to how the board software handles &lt;CODE&gt;&amp;lt;&amp;gt;&lt;/CODE&gt; characters.&lt;/P&gt;

&lt;P&gt;And please post any relevant props.conf settings your tried so far.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 11:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429698#M75263</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-07-09T11:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429699#M75264</link>
      <description>&lt;P&gt;Thanks Frank, please see updates! any help appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 12:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429699#M75264</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2018-07-09T12:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429700#M75265</link>
      <description>&lt;P&gt;Couple of comments:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I don't think you should mix "break only before" and "line breaker" in 1 props.conf. &lt;/LI&gt;
&lt;LI&gt;Line Breaker should have a capturing group (usually the line ending before the start of the event). &lt;/LI&gt;
&lt;LI&gt;don't add those &lt;CODE&gt;.+&lt;/CODE&gt; around time prefix and line breaker, no need for it and especially in the line breaker case it completely defeats the purpose of that setting&lt;/LI&gt;
&lt;LI&gt;TIME_PREFIX is a regex, so &lt;CODE&gt;&amp;lt;&amp;gt;&lt;/CODE&gt; characters need to be escaped.&lt;/LI&gt;
&lt;LI&gt;I guess you meant &lt;CODE&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/CODE&gt; not &lt;CODE&gt;MAX_TIMESTAMP&lt;/CODE&gt;.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Can you try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; CHARSET=UTF-16LE
 SHOULD_LINEMERGE=false
 disabled=false
 TIME_FORMAT=%Y-%m-%dT%H:%M:%S
 TIME_PREFIX=\&amp;lt;ReadTime\&amp;gt;
 MAX_TIMESTAMP_LOOKAHEAD=18
 LINE_BREAKER=([\r\n]+)\&amp;lt;GPO\sxmlns:xsd
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 09 Jul 2018 12:18:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429700#M75265</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-07-09T12:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429701#M75266</link>
      <description>&lt;P&gt;Thanks Frank!&lt;BR /&gt;
This changes to capture EVERYTHING as one event, doesn't seem to be breaking at the &lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 12:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429701#M75266</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2018-07-09T12:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429702#M75267</link>
      <description>&lt;P&gt;Your sample file contains a space before the &lt;CODE&gt;&amp;lt;GPO...&lt;/CODE&gt; tag. Is that also there in the actual data? If so, you need to add change the line breaker to: &lt;CODE&gt;([\r\n]+\s+)\&amp;lt;GPO\sxmlns:xsd&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 12:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429702#M75267</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-07-09T12:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why won't Splunk parse my multi-line event properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429703#M75268</link>
      <description>&lt;P&gt;Your original change worked, i accidentally copied the "=" from the Line Breaker!&lt;BR /&gt;
Thank you very much!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 14:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-won-t-Splunk-parse-my-multi-line-event-properly/m-p/429703#M75268</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2018-07-09T14:17:05Z</dc:date>
    </item>
  </channel>
</rss>

