<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to write regex to event break a multi line file into single event? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527090#M88903</link>
    <description>&lt;P&gt;hey tried the same but that is not working&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;LINE_BREAKER=([\r\n]+)\}()\{id:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2020 13:41:29 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2020-10-29T13:41:29Z</dc:date>
    <item>
      <title>How to write regex to event break a multi line file into single event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527013#M88884</link>
      <description>&lt;P&gt;I have multi line file (_json), which I am trying to create a individual events, the multi line file contains array of id, message and timestamp.&lt;/P&gt;&lt;P&gt;Sample Event data:&amp;nbsp;&lt;/P&gt;&lt;P&gt;{ [-]&lt;BR /&gt;logEvents: [ [-]&lt;BR /&gt;{ [-]&lt;BR /&gt;id: 3576745055635743000077342515139507954347666517578940416&lt;BR /&gt;message: START RequestId: 4e1251df-11d9-55d0-918a-09bb06b96122 Version: $LATEST&lt;/P&gt;&lt;P&gt;timestamp: 1603867953198&lt;BR /&gt;}&lt;BR /&gt;{ [+]&lt;BR /&gt;}&lt;BR /&gt;{ [-]&lt;BR /&gt;id: 35767450557316368740614159310005543840071546062336098306&lt;BR /&gt;message: [2020-10-28T06:52:33.240Z][4e1251df-11d9-55d0-918c-09cc06b96122][INFO][wfm-test2-lmd-towSyncWorkOrderWOM][HeaderProcessor.py, 23][The filtered request headers are {"test-PartyID": "test"}]&lt;/P&gt;&lt;P&gt;timestamp: 1603867953241&lt;BR /&gt;}&lt;BR /&gt;{ [+]&lt;BR /&gt;}&lt;BR /&gt;{ [-]&lt;BR /&gt;id: 3576745057558067905821073966314329716666554135734059012&lt;BR /&gt;message: [2020-10-28T06:52:34.59Z][4e1251df-11d9-55d0-918c-09cc06b96122][INFO][wfm-test2-lmd-towSyncWorkOrderWOM][lambda_function.py, 37][Response received from SNOW with status code :202 and response as {"result":{"message":"Message has been received!","value":"WOR200033942808"}}]&lt;/P&gt;&lt;P&gt;timestamp: 1603867954060&lt;BR /&gt;}&lt;BR /&gt;{ [+]&lt;BR /&gt;}&lt;BR /&gt;{ [+]&lt;BR /&gt;}&lt;BR /&gt;]&lt;BR /&gt;logGroup: /aws/lambda/wfm-test2-lmd-towSyncWorkOrderWOM&lt;BR /&gt;logStream: 2020/10/28/[$LATEST]0e5e38b8bf8e4247a5f063e5e1fdaf51&lt;BR /&gt;messageType: DATA_MESSAGE&lt;BR /&gt;owner: 126208963777&lt;BR /&gt;subscriptionFilters: [ [+]&lt;BR /&gt;]&lt;/P&gt;&lt;P&gt;Can you please guide me how to break this multi line event using the line breaker.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 07:55:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527013#M88884</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-10-29T07:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to write regex to event break a multi line file into single event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527078#M88896</link>
      <description>&lt;P&gt;Have you tried&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = \}()\{id:&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 29 Oct 2020 13:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527078#M88896</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-29T13:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to write regex to event break a multi line file into single event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527090#M88903</link>
      <description>&lt;P&gt;hey tried the same but that is not working&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;LINE_BREAKER=([\r\n]+)\}()\{id:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 13:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527090#M88903</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-10-29T13:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to write regex to event break a multi line file into single event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527194#M88919</link>
      <description>&lt;P&gt;Hey I was able to break the multi line events into single events using the below stanza&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;LINE_BREAKER=(\[|,\s*|\], )({"id":|"logGroup":)&lt;BR /&gt;disabled=false&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=13&lt;BR /&gt;TIME_FORMAT=%s%3Q&lt;BR /&gt;TIME_PREFIX="timestamp":\s+&lt;BR /&gt;TZ=UTC&lt;BR /&gt;TRUNCATE=100000&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 02:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-regex-to-event-break-a-multi-line-file-into-single/m-p/527194#M88919</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-10-30T02:31:11Z</dc:date>
    </item>
  </channel>
</rss>

