<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LINE_BREAKER settings works when adding input manually but not through props.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526379#M88799</link>
    <description>Have you any HF between UF and indexer? If yes the you must put props.conf to the first HF counting from UF. If not then, please try what the next command said&lt;BR /&gt;splunk btool props list -debug snort_unified2&lt;BR /&gt;r. Ismo</description>
    <pubDate>Sun, 25 Oct 2020 20:22:06 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-10-25T20:22:06Z</dc:date>
    <item>
      <title>LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526070#M88760</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to add Snort data into Splunk by monitoring barnyard2.alert file using Universal Forwarders.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///var/log/barnyard2/barnyard2.alert]
sourcetype=snort_unified2
index=snort&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As explained here &lt;A href="https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-line-breaking-a-single-IDS-Alert-event-into-two/m-p/287641#M54947" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-line-breaking-a-single-IDS-Alert-event-into-two/m-p/287641#M54947&lt;/A&gt; , I added same settings to props.conf(Indexer and SH) but Splunk still ends up breaking each line as a separate event, as shown below:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snort_1.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11444i3763D8A7770F6C95/image-size/large?v=v2&amp;amp;px=999" role="button" title="Snort_1.png" alt="Snort_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[snort_unified2]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)\[\*\*\]
TIME_PREFIX = ^([^\r\n]+[\r\n]+){2}
MAX_TIMESTAMP_LOOKAHEAD = 25
TIME_FORMAT = %m/%d-%H:%M:%S.%6N
category = Network &amp;amp; Security&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I try these settings by manually adding same input it works just fine.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snort_manual.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11445i2FE463C99448C919/image-size/large?v=v2&amp;amp;px=999" role="button" title="snort_manual.png" alt="snort_manual.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas on what could be going wrong with props.conf?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;~Abhi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 16:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526070#M88760</guid>
      <dc:creator>att35</dc:creator>
      <dc:date>2020-10-22T16:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526093#M88763</link>
      <description>&lt;P&gt;Did you restart the indexers after changing the props.conf file?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 19:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526093#M88763</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-22T19:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526101#M88765</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Yes. Both Indexer and the Search Head were restarted after making the props.conf change.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;~ Abhi&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 20:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526101#M88765</guid>
      <dc:creator>att35</dc:creator>
      <dc:date>2020-10-22T20:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526158#M88778</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/179828"&gt;@att35&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check props.conf on your UF or try using btool command.&lt;/P&gt;&lt;P&gt;Please let&amp;nbsp; me know if it helps or you found solution already.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 01:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526158#M88778</guid>
      <dc:creator>samcyber20</dc:creator>
      <dc:date>2020-10-23T01:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526213#M88783</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226521"&gt;@samcyber20&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;App that we pushed on the endpoints to collect these logs does not have any props.conf. Only inputs.conf with one stanza as I mentioned above.&lt;/P&gt;&lt;P&gt;Does it need a props as well with any of the entries that I added on the Indexer side?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;~ Abhi&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 12:21:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526213#M88783</guid>
      <dc:creator>att35</dc:creator>
      <dc:date>2020-10-23T12:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526378#M88798</link>
      <description>&lt;P&gt;This is an index time setting and therefore not required at universal forwarder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what you can try:&lt;/P&gt;&lt;PRE&gt;SHOULD_LINEMERGE= true&lt;BR /&gt;&lt;BR /&gt;Along with one of:&lt;BR /&gt;BREAK_ONLY_BEFORE,&lt;BR /&gt;BREAK_ONLY_AFTER&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 25 Oct 2020 19:33:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526378#M88798</guid>
      <dc:creator>kbehl</dc:creator>
      <dc:date>2020-10-25T19:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526379#M88799</link>
      <description>Have you any HF between UF and indexer? If yes the you must put props.conf to the first HF counting from UF. If not then, please try what the next command said&lt;BR /&gt;splunk btool props list -debug snort_unified2&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sun, 25 Oct 2020 20:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526379#M88799</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-25T20:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: LINE_BREAKER settings works when adding input manually but not through props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526388#M88800</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/179828"&gt;@att35&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;use btool command mentioned by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; .&lt;/P&gt;&lt;P&gt;It will give you much more idea.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sam&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2020 23:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LINE-BREAKER-settings-works-when-adding-input-manually-but-not/m-p/526388#M88800</guid>
      <dc:creator>samcyber20</dc:creator>
      <dc:date>2020-10-25T23:20:32Z</dc:date>
    </item>
  </channel>
</rss>

