<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Line breaking not working for JSON logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509835#M86702</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp; this props.conf is working fine for my logs.... &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jul 2020 14:44:21 GMT</pubDate>
    <dc:creator>asimasplunk</dc:creator>
    <dc:date>2020-07-18T14:44:21Z</dc:date>
    <item>
      <title>Line breaking not working for JSON logs (API at heavy forwarder).</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507631#M86390</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are using ingest pattern as API at Heavy forwarder.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;props.conf:-&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[kenna:applications]
INDEXED_EXTRACTIONS = json
TZ = UTC
LINE_BREAKER = "\}\,\{\"id\"\:
TRUNCATE = 10485760
SHOULD_LINEMERGE = false&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;This line breaker did not work&lt;BR /&gt;&lt;BR /&gt;Sample Log:-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"applications":[{"id":3964,"name":"xyz.com","repo_url":null,"host_name":null,"owner":null,"team_name":null,"business_units":null,"notes":null,"risk_meter_score":0,"vulnerability_count":0,"asset_count":0,"total_vulnerability_count":0,"open_vulnerability_count_by_risk_level":{"high":0,"medium":0,"low":0,"total":0},"historical_risk_meter_scores":[{"date":"2020-04-07","score":0},{"date":"2020-04-08","score":0},{"date":"2020-04-09","score":0},{"date":"2020-04-10","score":0},{"date":"2020-04-11","score":0},{"date":"2020-04-12","score":0},{"date":"2020-04-13","score":0},{"date":"2020-04-14","score":0},{"date":"2020-04-15","score":0},{"date":"2020-04-16","score":0},{"date":"2020-04-17","score":0},{"date":"2020-04-18","score":0},{"date":"2020-04-19","score":0},{"date":"2020-04-20","score":0},{"date":"2020-04-21","score":0},{"date":"2020-04-22","score":0},{"date":"2020-04-23","score":0},{"date":"2020-04-24","score":0},{"date":"2020-04-25","score":0},{"date":"2020-04-26","score":0},{"date":"2020-04-27","score":0},{"date":"2020-04-28","score":0},{"date":"2020-04-29","score":0},{"date":"2020-04-30","score":0},{"date":"2020-05-01","score":0},{"date":"2020-05-02","score":0},{"date":"2020-05-03","score":0},{"date":"2020-05-04","score":0},{"date":"2020-05-05","score":0},{"date":"2020-05-06","score":0},{"date":"2020-05-07","score":0},{"date":"2020-05-08","score":0},{"date":"2020-05-09","score":0},{"date":"2020-05-10","score":0},{"date":"2020-05-11","score":0},{"date":"2020-05-12","score":0},{"date":"2020-05-13","score":0},{"date":"2020-05-14","score":0},{"date":"2020-05-15","score":0},{"date":"2020-05-16","score":0},{"date":"2020-05-17","score":0},{"date":"2020-05-18","score":0},{"date":"2020-05-19","score":0},{"date":"2020-05-20","score":0},{"date":"2020-05-21","score":0},{"date":"2020-05-22","score":0},{"date":"2020-05-23","score":0},{"date":"2020-05-24","score":0},{"date":"2020-05-25","score":0},{"date":"2020-05-26","score":0},{"date":"2020-05-27","score":0},{"date":"2020-05-28","score":0},{"date":"2020-05-29","score":0},{"date":"2020-05-30","score":0},{"date":"2020-05-31","score":0},{"date":"2020-06-01","score":0},{"date":"2020-06-02","score":0},{"date":"2020-06-03","score":0},{"date":"2020-06-04","score":0},{"date":"2020-06-05","score":0},{"date":"2020-06-06","score":0},{"date":"2020-06-07","score":0},{"date":"2020-06-08","score":0},{"date":"2020-06-09","score":0},{"date":"2020-06-10","score":0},{"date":"2020-06-11","score":0},{"date":"2020-06-12","score":0},{"date":"2020-06-13","score":0},{"date":"2020-06-14","score":0},{"date":"2020-06-15","score":0},{"date":"2020-06-16","score":0},{"date":"2020-06-17","score":0},{"date":"2020-06-18","score":0},{"date":"2020-06-19","score":0},{"date":"2020-06-20","score":0},{"date":"2020-06-21","score":0},{"date":"2020-06-22","score":0},{"date":"2020-06-23","score":0},{"date":"2020-06-24","score":0},{"date":"2020-06-25","score":0},{"date":"2020-06-26","score":0},{"date":"2020-06-27","score":0},{"date":"2020-06-28","score":0},{"date":"2020-06-29","score":0},{"date":"2020-06-30","score":0},{"date":"2020-07-01","score":0},{"date":"2020-07-02","score":0},{"date":"2020-07-03","score":0},{"date":"2020-07-04","score":0},{"date":"2020-07-05","score":0},{"date":"2020-07-06","score":0}],"external_facing":true,"priority":10,"identifiers":["xyz.com"]},{"id":3965,"name":"xyz1.com/ecmlogin- DEV","repo_url":null,"host_name":null,"owner":null,"team_name":null,"business_units":null,"notes":null,"risk_meter_score":0,"vulnerability_count":0,"asset_count":0,"total_vulnerability_count":0,"open_vulnerability_count_by_risk_level":{"high":0,"medium":0,"low":0,"total":0},"historical_risk_meter_scores":[{"date":"2020-04-07","score":0},{"date":"2020-04-08","score":0},{"date":"2020-04-09","score":0},{"date":"2020-04-10","score":0},{..........&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 18:40:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507631#M86390</guid>
      <dc:creator>asimasplunk</dc:creator>
      <dc:date>2020-07-06T18:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking not working for JSON logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507633#M86392</link>
      <description>Where do you expect/want the event to break?&lt;BR /&gt;There is no text matching '"},{"id":'.</description>
      <pubDate>Mon, 06 Jul 2020 17:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507633#M86392</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-06T17:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking not working for JSON logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507638#M86394</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Each log has a unique id. so we want to break every logs from&amp;nbsp;&lt;STRONG&gt;},{"id":&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 17:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507638#M86394</guid>
      <dc:creator>asimasplunk</dc:creator>
      <dc:date>2020-07-06T17:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking not working for JSON logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507646#M86397</link>
      <description>&lt;P&gt;Well then that is what should be the line breaker.&amp;nbsp; Also, every &lt;FONT face="courier new,courier"&gt;LINE_BREAKER&lt;/FONT&gt; setting must contain a capture group.&amp;nbsp; Try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = }(,){"id":&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 17:59:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/507646#M86397</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-06T17:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking not working for JSON logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509466#M86662</link>
      <description>&lt;P&gt;Try something like&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = {"id"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 16 Jul 2020 07:42:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509466#M86662</guid>
      <dc:creator>sumanssah</dc:creator>
      <dc:date>2020-07-16T07:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking not working for JSON logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509824#M86700</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[kenna:applications]
TZ=UTC
KV_MODE=json
TRUNCATE=0
SHOULD_LINEMERGE=false
category=Structured
disabled=false
pulldown_type=true
LINE_BREAKER=(.){"id
SEDCMD-json=s/({.*})]}/\1/ s/.*applications.*//&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LINE_BREAKER breaks JSON format.&amp;nbsp;&lt;BR /&gt;try&amp;nbsp; SEDCMD and KV_MODE=json&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 02:42:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509824#M86700</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-18T02:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking not working for JSON logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509835#M86702</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp; this props.conf is working fine for my logs.... &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 14:44:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-breaking-not-working-for-JSON-logs-API-at-heavy-forwarder/m-p/509835#M86702</guid>
      <dc:creator>asimasplunk</dc:creator>
      <dc:date>2020-07-18T14:44:21Z</dc:date>
    </item>
  </channel>
</rss>

