<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Line break doesn't work in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455214#M78747</link>
    <description>&lt;P&gt;The space before "INICIO REPORTE" was missed and LINE_BREAKER is misspelled. Make this change to the config and it should work.&lt;/P&gt;

&lt;P&gt;LINE_BRAKER = ([\r\n]+)(?=\d+\s+&amp;lt;[^&amp;gt;]+&amp;gt;=+INICIO REPORTE)&lt;BR /&gt;
to&lt;BR /&gt;
LINE_BREAKER = ([\r\n]+)(?=\d+\s+&amp;lt;[^&amp;gt;]+&amp;gt;=+\s+INICIO REPORTE)&lt;/P&gt;

&lt;P&gt;If you are using LINE_BREAKER then you should set SHOULD_LINEMERGE = false. From the Splunk documentation on props.conf:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;NOTE: You get a significant boost to processing speed when you use
LINE_BREAKER to delimit multi-line events (as opposed to using
SHOULD_LINEMERGE to reassemble individual lines into multi-line events).

&lt;UL&gt;
&lt;LI&gt;When using LINE_BREAKER to delimit events, SHOULD_LINEMERGE should be set
to false, to ensure no further combination of delimited events occurs.&lt;/LI&gt;
&lt;LI&gt;Using LINE_BREAKER to delimit events is discussed in more detail in the 
documentation. Search the documentation for "configure event line breaking" 
for details.&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:34:12 GMT</pubDate>
    <dc:creator>rmjharris</dc:creator>
    <dc:date>2020-09-30T00:34:12Z</dc:date>
    <item>
      <title>Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455210#M78743</link>
      <description>&lt;P&gt;I have following configuration&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;P&gt;[Scheduler]&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
category = Custom&lt;BR /&gt;
pulldown_type = 1&lt;BR /&gt;
disabled = false&lt;BR /&gt;
BREAK_ONLY_BEFORE = INICIO REPORTE&lt;/P&gt;

&lt;P&gt;But line breaking doesn't work correctly in event in &lt;STRONG&gt;bold&lt;/STRONG&gt;. &lt;/P&gt;

&lt;P&gt;5/13/19&lt;BR /&gt;
12:44:41.000 PM &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:41&amp;gt;==================== INICIO REPORTE ======================&lt;BR /&gt;
17109 Query :(sta..SP_STA_MON_OBTIENE_TAREAS 17109,1)&lt;BR /&gt;
17109 RESPUESTA DE TAREAS PENDIENTES&lt;BR /&gt;
Ret :0, nFilas : 17, nCols :1&lt;BR /&gt;
Error:()&lt;BR /&gt;
17109 ID. Tarea :(669153) Periodo Tarea :(201905)&lt;BR /&gt;
17109 Nombre Tarea :(Traduccion - Conversion Archivo) Path Tarea :(/redbanc/bin_STI/bin/TAREA_CONVIERTE_ARCHIVOS)&lt;BR /&gt;
17109 NUm. Params :(11)&lt;BR /&gt;
17109 i :14, tot :17,EJECUTAR :[/redbanc/bin_STI/bin/TAREA_CONVIERTE_ARCHIVOS]&lt;BR /&gt;
17109 Arg 0:[/redbanc/bin_STI/bin/TAREA_CONVIERTE_ARCHIVOS]&lt;BR /&gt;
17109 Arg 1:[669153]&lt;BR /&gt;
17109 Arg 2:[201905]&lt;BR /&gt;
17109 Arg 3:[/redbanc/sca/casillas_STI/data/0008/2019050001182737REN00203715220190511]&lt;BR /&gt;
17109 Arg 4:[/redbanc/sca/casillas_STI/data/0008/2019050000669164REN00203715220190511]&lt;BR /&gt;
17109 Arg 5:[/0008]&lt;BR /&gt;
17109 Arg 6:[/redbanc/sca/casillas_STI/data/0002/2019050001182738REN00203715220190511.CTR]&lt;BR /&gt;
17109 Arg 7:[1]&lt;BR /&gt;
17109 Arg 8:[1]&lt;BR /&gt;
17109 Arg 9:[1]&lt;BR /&gt;
17109 Arg 10:[1]&lt;BR /&gt;
17109 Arg 11:[0]&lt;BR /&gt;
17109 Arg 12:[607:83:44:21 9102 31 yaM7372811509102]&lt;BR /&gt;
17109 Arg 13:[70]&lt;BR /&gt;
17109 Se libera memoria de parametros : 13/05/2019 - 12:44:41 &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:41&amp;gt;==================== FIN REPORTE =====================&lt;/P&gt;

&lt;P&gt;5/13/19&lt;BR /&gt;
12:44:41.000 PM &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:41&amp;gt;==================== INICIO REPORTE ======================&lt;BR /&gt;
17109 Query :(sta..SP_STA_MON_OBTIENE_TAREAS 17109,1)&lt;BR /&gt;
17109 RESPUESTA DE TAREAS PENDIENTES&lt;BR /&gt;
Ret :0, nFilas : 17, nCols :1&lt;BR /&gt;
Error:()&lt;BR /&gt;
17109 ID. Tarea :(669157) Periodo Tarea :(201905)&lt;BR /&gt;
17109 Nombre Tarea :(Traduccion - Conversion Archivo) Path Tarea :(/redbanc/bin_STI/bin/TAREA_CONVIERTE_ARCHIVOS)&lt;BR /&gt;
17109 NUm. Params :(11)&lt;BR /&gt;
17109 i :14, tot :17,EJECUTAR :[/redbanc/bin_STI/bin/TAREA_CONVIERTE_ARCHIVOS]&lt;BR /&gt;
17109 Arg 0:[/redbanc/bin_STI/bin/TAREA_CONVIERTE_ARCHIVOS]&lt;BR /&gt;
17109 Arg 1:[669157]&lt;BR /&gt;
17109 Arg 2:[201905]&lt;BR /&gt;
17109 Arg 3:[/redbanc/sca/casillas_STI/data/0009/2019050001182739REN00203715220190512]&lt;BR /&gt;
17109 Arg 4:[/redbanc/sca/casillas_STI/data/0009/2019050000669165REN00203715220190512]&lt;BR /&gt;
17109 Arg 5:[/0009]&lt;BR /&gt;
17109 Arg 6:[/redbanc/sca/casillas_STI/data/0000/2019050001182740REN00203715220190512.CTR]&lt;BR /&gt;
17109 Arg 7:[1]&lt;BR /&gt;
17109 Arg 8:[1]&lt;BR /&gt;
17109 Arg 9:[1]&lt;BR /&gt;
17109 Arg 10:[1]&lt;BR /&gt;
17109 Arg 11:[0]&lt;BR /&gt;
17109 Arg 12:[617:93:44:21 9102 31 yaM9372811509102]&lt;BR /&gt;
17109 Arg 13:[71]&lt;BR /&gt;
17109 Se libera memoria de parametros : 13/05/2019 - 12:44:41 &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:41&amp;gt;==================== FIN REPORTE =====================&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;5/13/19&lt;BR /&gt;
12:44:41.000 PM &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:41&amp;gt;==================== INICIO REPORTE ======================&lt;BR /&gt;
17109 Query :(sta..SP_STA_MON_OBTIENE_TAREAS 17109,1)&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;5/13/19&lt;BR /&gt;
12:44:41.000 PM &lt;BR /&gt;
17109 RESPUESTA DE TAREAS PENDIENTES&lt;BR /&gt;
Ret :0, nFilas : 1, nCols :1&lt;BR /&gt;
Error:()&lt;BR /&gt;
17109 NO HAY TAREA&lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:41&amp;gt;==================== FIN REPORTE =====================&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;5/13/19&lt;BR /&gt;
12:44:44.000 PM &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:44&amp;gt;==================== INICIO REPORTE ======================&lt;BR /&gt;
17109 Query :(sta..SP_STA_MON_OBTIENE_TAREAS 17109,1)&lt;BR /&gt;
17109 RESPUESTA DE TAREAS PENDIENTES&lt;BR /&gt;
Ret :0, nFilas : 11, nCols :1&lt;BR /&gt;
Error:()&lt;BR /&gt;
17109 ID. Tarea :(669127) Periodo Tarea :(201905)&lt;BR /&gt;
17109 Nombre Tarea :(Generacion de Archivo Aviso) Path Tarea :(/redbanc/bin_STI/bin/TAREA_GENERA_AVI)&lt;BR /&gt;
17109 NUm. Params :(5)&lt;BR /&gt;
17109 i :8, tot :11,EJECUTAR :[/redbanc/bin_STI/bin/TAREA_GENERA_AVI]&lt;BR /&gt;
17109 Arg 0:[/redbanc/bin_STI/bin/TAREA_GENERA_AVI]&lt;BR /&gt;
17109 Arg 1:[669127]&lt;BR /&gt;
17109 Arg 2:[201905]&lt;BR /&gt;
17109 Arg 3:[/redbanc/sca/casillas_STI/data/0005/2019050000669127REN00202715220190512.AVI]&lt;BR /&gt;
17109 Arg 4:[REN00202715220190512]&lt;BR /&gt;
17109 Arg 5:[cca777p]&lt;BR /&gt;
17109 Arg 6:[/0005]&lt;BR /&gt;
17109 Arg 7:[LA TRANSMISIÓN DEL ARCHIVOS REN00202715220190512 HA LLEGADO SATISFACTORIAMENTE.]&lt;BR /&gt;
17109 Se libera memoria de parametros : 13/05/2019 - 12:44:44 &lt;BR /&gt;
17109 &amp;lt;13/05/2019 - 12:44:44&amp;gt;==================== FIN REPORTE =====================&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:30:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455210#M78743</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2020-09-30T00:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455211#M78744</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Scheduler]
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
LINE_BRAKER = ([\r\n]+)(?=\d+\s+\&amp;lt;[^\&amp;gt;]+\&amp;gt;\=+INICIO REPORTE)
TIME_PREFIX = ^\d+\s+\&amp;lt;
TIME_FORMAT = %d/%m/%Y - %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD = 21
category = Custom
pulldown_type = 1
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 May 2019 18:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455211#M78744</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-05-14T18:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455212#M78745</link>
      <description>&lt;P&gt;Why should_linemerge=false?&lt;/P&gt;

&lt;P&gt;I understand that should_linemerge=true for multi-line events?&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 18:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455212#M78745</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2019-05-14T18:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455213#M78746</link>
      <description>&lt;P&gt;@somesoni2 doesn't work. I tested and this happened&lt;/P&gt;

&lt;P&gt;1/15/19&lt;BR /&gt;
5:31:24.000 PM&lt;BR /&gt;&lt;BR /&gt;
3457 &amp;lt;15/01/2019 - 17:31:24&amp;gt;==================== INICIO REPORTE ======================&lt;BR /&gt;
3457 ID Tarea             :(844205)&lt;BR /&gt;
3457 Nombre Archivo AVI   :(/redbanc/sca/casillas_STI/data/0006/2019010000844205RPT028190115172140.AVI)&lt;BR /&gt;
3457 Nombre Archivo Datos :(RPT028190115172140  )&lt;BR /&gt;
3457 Casilla Origen       :(cca777p             )&lt;BR /&gt;
&lt;STRONG&gt;Show all 144 lines&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I have unique event with several lines&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 20:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455213#M78746</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2019-05-14T20:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455214#M78747</link>
      <description>&lt;P&gt;The space before "INICIO REPORTE" was missed and LINE_BREAKER is misspelled. Make this change to the config and it should work.&lt;/P&gt;

&lt;P&gt;LINE_BRAKER = ([\r\n]+)(?=\d+\s+&amp;lt;[^&amp;gt;]+&amp;gt;=+INICIO REPORTE)&lt;BR /&gt;
to&lt;BR /&gt;
LINE_BREAKER = ([\r\n]+)(?=\d+\s+&amp;lt;[^&amp;gt;]+&amp;gt;=+\s+INICIO REPORTE)&lt;/P&gt;

&lt;P&gt;If you are using LINE_BREAKER then you should set SHOULD_LINEMERGE = false. From the Splunk documentation on props.conf:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;NOTE: You get a significant boost to processing speed when you use
LINE_BREAKER to delimit multi-line events (as opposed to using
SHOULD_LINEMERGE to reassemble individual lines into multi-line events).

&lt;UL&gt;
&lt;LI&gt;When using LINE_BREAKER to delimit events, SHOULD_LINEMERGE should be set
to false, to ensure no further combination of delimited events occurs.&lt;/LI&gt;
&lt;LI&gt;Using LINE_BREAKER to delimit events is discussed in more detail in the 
documentation. Search the documentation for "configure event line breaking" 
for details.&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455214#M78747</guid>
      <dc:creator>rmjharris</dc:creator>
      <dc:date>2020-09-30T00:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455215#M78748</link>
      <description>&lt;P&gt;@rmjharris Thanks work fine. Monitor if the line breaking work correctly&lt;/P&gt;

&lt;P&gt;How do you explain how work this regex please?&lt;/P&gt;

&lt;P&gt;In the other hand, why there are two capturing groups?&lt;/P&gt;

&lt;P&gt;Sorry, i'm new in this.&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 13:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455215#M78748</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2019-05-15T13:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Line break doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455216#M78749</link>
      <description>&lt;P&gt;From the &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/Propsconf" target="_blank"&gt;props.conf&lt;/A&gt; documentation:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;LINE_BREAKER = &lt;BR /&gt;
* Specifies a regex that determines how the raw text stream is broken into&lt;BR /&gt;
  initial events, before line merging takes place. (See the SHOULD_LINEMERGE&lt;BR /&gt;
  setting, below)&lt;BR /&gt;
* Defaults to ([\r\n]+), meaning data is broken into an event for each line,&lt;BR /&gt;
  delimited by any number of carriage return or newline characters.&lt;BR /&gt;
* The regex must contain a capturing group -- a pair of parentheses which&lt;BR /&gt;
  defines an identified subcomponent of the match.&lt;BR /&gt;
* Wherever the regex matches, Splunk software considers the start of the first&lt;BR /&gt;
  capturing group to be the end of the previous event, and considers the end&lt;BR /&gt;
  of the first capturing group to be the start of the next event.&lt;BR /&gt;
* The contents of the first capturing group are discarded, and will not be&lt;BR /&gt;
  present in any event.  You are telling Splunk software that this text comes &lt;BR /&gt;
  between lines.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So the first capture group matches and discards the return/new line but then you need to identify the start of the event not just create a new event at each new line. Since Splunk discards the contents of the first capture group you need to create a second that won't be discarded.&lt;/P&gt;

&lt;P&gt;In this case &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt; wrote the second part as an assertion rather than a capture group. You can read about the difference &lt;A href="https://www.regular-expressions.info/lookaround.html" target="_blank"&gt;here&lt;/A&gt;. You can remove the ?= and it should work as well. &lt;/P&gt;

&lt;P&gt;If it's working for you make sure you mark this correct. &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt; did 99% of the work I just corrected a minor mistake.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-break-doesn-t-work/m-p/455216#M78749</guid>
      <dc:creator>rmjharris</dc:creator>
      <dc:date>2020-09-30T00:31:00Z</dc:date>
    </item>
  </channel>
</rss>

