<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Line Break in multiline event doesn't work in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532329#M89497</link>
    <description>&lt;P&gt;Hello fellow splunkers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;atm I'm trying to break up a huge multiline event that is merged together with &amp;amp;&amp;amp;&amp;amp;. When I try to explicitly tell Splunk to &lt;STRONG&gt;BREAK_ONLY_AFTER = &amp;amp;&amp;amp;&amp;amp;&lt;/STRONG&gt; it doesn't work. I also tried &lt;STRONG&gt;BREAK_ONLY_BEFORE = \d+.\d+.\d+.\d+\s-\s-&lt;/STRONG&gt; and &lt;STRONG&gt;BREAK_ONLY_AFTER = \d{3}&amp;amp;&amp;amp;&amp;amp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;it seems that nothing I try works. please help&lt;/P&gt;&lt;P&gt;here is the source log:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;141.146.8.66 - - [13/Jan/2016 21:03:09:200] "POST /category.screen?category_id=SURPRISE&amp;amp;JSESSIONID=SD1SL2FF5ADFF3 HTTP 1.1" 200 3496 "http://www.myflowershop.com/cart.do?action=view&amp;amp;itemId=EST-16&amp;amp;product_id=RP-SN-01" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.38 Safari/533.4" 294&amp;amp;&amp;amp;&amp;amp;130.253.37.97 - - [13/Jan/2016 21:03:09:185] "GET /category.screen?category_id=BOUQUETS&amp;amp;JSESSIONID=SD7SL2FF1ADFF8 HTTP 1.1" 200 2320 "http://www.myflowershop.com/cart.do?action=changequantity&amp;amp;itemId=EST-12&amp;amp;product_id=AV-CB-01" "Opera/9.20 (Windows NT 6.0; U; en)" 361&amp;amp;&amp;amp;&amp;amp;141.146.8.66 - - [13/Jan/2016 21:03:09:167] "GET /product.screen?product_id=RP-LI-02&amp;amp;JSESSIONID=SD9SL9FF8ADFF1 HTTP 1.1" 200 3855 "http://www.myflowershop.com/cart.do?action=changequantity&amp;amp;itemId=EST-20&amp;amp;product_id=RP-LI-02" "Googlebot/2.1 ( http://www.googlebot.com/bot.html) " 929&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 13:37:27 GMT</pubDate>
    <dc:creator>avoelk</dc:creator>
    <dc:date>2020-12-08T13:37:27Z</dc:date>
    <item>
      <title>Line Break in multiline event doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532329#M89497</link>
      <description>&lt;P&gt;Hello fellow splunkers!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;atm I'm trying to break up a huge multiline event that is merged together with &amp;amp;&amp;amp;&amp;amp;. When I try to explicitly tell Splunk to &lt;STRONG&gt;BREAK_ONLY_AFTER = &amp;amp;&amp;amp;&amp;amp;&lt;/STRONG&gt; it doesn't work. I also tried &lt;STRONG&gt;BREAK_ONLY_BEFORE = \d+.\d+.\d+.\d+\s-\s-&lt;/STRONG&gt; and &lt;STRONG&gt;BREAK_ONLY_AFTER = \d{3}&amp;amp;&amp;amp;&amp;amp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;it seems that nothing I try works. please help&lt;/P&gt;&lt;P&gt;here is the source log:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;141.146.8.66 - - [13/Jan/2016 21:03:09:200] "POST /category.screen?category_id=SURPRISE&amp;amp;JSESSIONID=SD1SL2FF5ADFF3 HTTP 1.1" 200 3496 "http://www.myflowershop.com/cart.do?action=view&amp;amp;itemId=EST-16&amp;amp;product_id=RP-SN-01" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.38 Safari/533.4" 294&amp;amp;&amp;amp;&amp;amp;130.253.37.97 - - [13/Jan/2016 21:03:09:185] "GET /category.screen?category_id=BOUQUETS&amp;amp;JSESSIONID=SD7SL2FF1ADFF8 HTTP 1.1" 200 2320 "http://www.myflowershop.com/cart.do?action=changequantity&amp;amp;itemId=EST-12&amp;amp;product_id=AV-CB-01" "Opera/9.20 (Windows NT 6.0; U; en)" 361&amp;amp;&amp;amp;&amp;amp;141.146.8.66 - - [13/Jan/2016 21:03:09:167] "GET /product.screen?product_id=RP-LI-02&amp;amp;JSESSIONID=SD9SL9FF8ADFF1 HTTP 1.1" 200 3855 "http://www.myflowershop.com/cart.do?action=changequantity&amp;amp;itemId=EST-20&amp;amp;product_id=RP-LI-02" "Googlebot/2.1 ( http://www.googlebot.com/bot.html) " 929&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 13:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532329#M89497</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2020-12-08T13:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Line Break in multiline event doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532330#M89498</link>
      <description>&lt;P&gt;It doesn't work because there is no setting called BREAK_ONLY_AFTER.&amp;nbsp; There is BREAK_ONLY_BEFORE and MUST_BREAK_AFTER, however.&amp;nbsp; It's more efficient, however, to use LINE_BREAKER.&amp;nbsp; Try these props.conf settings.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[mysourcetype]
SHOULD_LINEMERGE = false
LINE_BREAKER = (&amp;amp;&amp;amp;&amp;amp;)
TIME_PREFIX = \[
TIME_FORMAT = %d/%b/%Y %H:%M:%S:%3N
MAX_TIMESTAMP_LOOKAHEAD = 23
TRUNCATE = 10000&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 08 Dec 2020 13:53:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532330#M89498</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-08T13:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Line Break in multiline event doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532331#M89499</link>
      <description>&lt;P&gt;I think I found a solution already as provided here:&lt;/P&gt;&lt;P&gt;&lt;A title="solution" href="https://community.splunk.com/t5/Getting-Data-In/Unable-to-break-Multi-line-event-into-single-event/m-p/492332" target="_blank" rel="noopener"&gt;Unable-to-break-Multi-line-event-into-single-event&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using LINE_BREAKER = it is apparently mandatory to encase your regex with () otherwise it doesn't work. I didn't know that. What I used, and what worked was one of the Regex I posted above but like this:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = (\d{3}&amp;amp;&amp;amp;&amp;amp;)&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 08 Dec 2020 13:53:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532331#M89499</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2020-12-08T13:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Line Break in multiline event doesn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532334#M89500</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;thanks for your answer, that's exactly what I just figured out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; thanks for your fast reply tho! if I wouldn't have tried this a minute ago this would've been my life saver.&lt;/P&gt;&lt;P&gt;and you're right - I missread props.conf.spec . What could be used is BREAK_ONLY_BEFORE or MUST_BREAK_AFTER&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 13:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Line-Break-in-multiline-event-doesn-t-work/m-p/532334#M89500</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2020-12-08T13:57:29Z</dc:date>
    </item>
  </channel>
</rss>

