<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log file looks like below. In this log file two events are there and remaining stack trace. Need to group these two events. For each error starts with extra time stamp &amp;quot;06:45:00,186&amp;quot;. How do we set values in Splunk prop file. Thanks in advance. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358632#M92951</link>
    <description>&lt;P&gt;FINEST|3016/0|16-11-03 06:45:00|06:45:00,186 ERROR [SecurityManagerAudit] [Overall test] [134981.test] &lt;A href="https://community.splunk.com/SecurityManager"&gt;&lt;/A&gt;.getGebruiker() nl.allshare.securitymanager.exceptions.SecurityManagerException: *** XMLSecurityMetaInfoService Exception voor Gebruiker: ADPNL00007821 &amp;gt;&amp;gt; &lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|    at nl.allshare.securitymanager.manager.modules.XMLSecurityMetaInfoService.getGebruiker(XMLSecurityMetaInfoService.java:89)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|    at nl.allshare.securitymanager.manager.modules.XMLSecurityMetaInfoService.getGebruiker(XMLSecurityMetaInfoService.java:69)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|    ... 22 more&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|06:46:12,189 ERROR [testing] [Overall test] [134985.test] &lt;A href="https://community.splunk.com/SecurityManager"&gt;&lt;/A&gt;.getGebruiker() nl.allshare.securitymanager.exceptions.SecurityManagerException: *** XMLSecurityMetaInfoService Exception voor &amp;gt;&amp;gt; &lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|    at nl.allshare.securitymanager.manager.modules.XMLSecurityMetaInfoService.getGebruiker(XMLSecurityMetaInfoService.java:89)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|    at nl.allshare.securitymanager.manager.utils.SecurityManager.getNotCachedGebruiker(SecurityManager.java:1369)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|    ... 22 more&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2017 16:03:15 GMT</pubDate>
    <dc:creator>sgurugubelli</dc:creator>
    <dc:date>2017-05-02T16:03:15Z</dc:date>
    <item>
      <title>Log file looks like below. In this log file two events are there and remaining stack trace. Need to group these two events. For each error starts with extra time stamp "06:45:00,186". How do we set values in Splunk prop file. Thanks in advance.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358632#M92951</link>
      <description>&lt;P&gt;FINEST|3016/0|16-11-03 06:45:00|06:45:00,186 ERROR [SecurityManagerAudit] [Overall test] [134981.test] &lt;A href="https://community.splunk.com/SecurityManager"&gt;&lt;/A&gt;.getGebruiker() nl.allshare.securitymanager.exceptions.SecurityManagerException: *** XMLSecurityMetaInfoService Exception voor Gebruiker: ADPNL00007821 &amp;gt;&amp;gt; &lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|    at nl.allshare.securitymanager.manager.modules.XMLSecurityMetaInfoService.getGebruiker(XMLSecurityMetaInfoService.java:89)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|    at nl.allshare.securitymanager.manager.modules.XMLSecurityMetaInfoService.getGebruiker(XMLSecurityMetaInfoService.java:69)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|    ... 22 more&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:45:00|&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|06:46:12,189 ERROR [testing] [Overall test] [134985.test] &lt;A href="https://community.splunk.com/SecurityManager"&gt;&lt;/A&gt;.getGebruiker() nl.allshare.securitymanager.exceptions.SecurityManagerException: *** XMLSecurityMetaInfoService Exception voor &amp;gt;&amp;gt; &lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|    at nl.allshare.securitymanager.manager.modules.XMLSecurityMetaInfoService.getGebruiker(XMLSecurityMetaInfoService.java:89)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|    at nl.allshare.securitymanager.manager.utils.SecurityManager.getNotCachedGebruiker(SecurityManager.java:1369)&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|    ... 22 more&lt;BR /&gt;
FINEST|3016/0|16-11-03 06:47:00|&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 16:03:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358632#M92951</guid>
      <dc:creator>sgurugubelli</dc:creator>
      <dc:date>2017-05-02T16:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Log file looks like below. In this log file two events are there and remaining stack trace. Need to group these two events. For each error starts with extra time stamp "06:45:00,186". How do we set values in Splunk prop file. Thanks in advance.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358633#M92952</link>
      <description>&lt;P&gt;In addition to above, I have tried with below settings in splunk Prop file. But still it doesn't group the events with stacktrace.&lt;/P&gt;

&lt;P&gt;[log4j]&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
BREAK_ONLY_BEFORE = [.&lt;EM&gt;?] [.&lt;/EM&gt;?] [.&lt;EM&gt;?] [.&lt;/EM&gt;?] (.*?)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:55:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358633#M92952</guid>
      <dc:creator>sgurugubelli</dc:creator>
      <dc:date>2020-09-29T13:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Log file looks like below. In this log file two events are there and remaining stack trace. Need to group these two events. For each error starts with extra time stamp "06:45:00,186". How do we set values in Splunk prop file. Thanks in advance.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358634#M92953</link>
      <description>&lt;P&gt;Could you please help us?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 05:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358634#M92953</guid>
      <dc:creator>sgurugubelli</dc:creator>
      <dc:date>2017-05-03T05:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Log file looks like below. In this log file two events are there and remaining stack trace. Need to group these two events. For each error starts with extra time stamp "06:45:00,186". How do we set values in Splunk prop file. Thanks in advance.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358635#M92954</link>
      <description>&lt;P&gt;Try the below settings for your sourcetype in props.conf -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[my_sourcetype]
TIME_PREFIX =^(?=([^\|]+\|){3})
TIME_FORMAT = %T,%3N
MAX_TIMESTAMP_LOOKAHEAD = 25
LINE_BREAKER = ([\n\r]+)(?=([^\|]+\|){3}(\d{2}\:){2}\d{2}\,\d{3}\s+)
SHOULD_LINEMERGE = False
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 May 2017 12:20:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-file-looks-like-below-In-this-log-file-two-events-are-there/m-p/358635#M92954</guid>
      <dc:creator>dineshraj9</dc:creator>
      <dc:date>2017-05-03T12:20:13Z</dc:date>
    </item>
  </channel>
</rss>

