<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic the beginning and end of the event in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136556#M97847</link>
    <description>&lt;P&gt;Hello, i have logs with some event.  I want see only my event. How i can remove another information. My event bigins at:"main: number of bytes received: 489"  and finish at: "Send msg to queue *******" Could you help me in skype digilan007&lt;/P&gt;

&lt;P&gt;6|  set_buffer_mode: stderr is line-buffered&lt;BR /&gt;
6|  Opened txrout.out, Mar 27 at 09:38:00&lt;/P&gt;

&lt;P&gt;6|  #!# SVFE Ver. 2.2.7 build 20050624 #!#&lt;BR /&gt;
6|  =&amp;gt;COMMIT_WORK (db_login.pc)&lt;BR /&gt;
0|  &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Task with ID = 11 is waiting for the message to arrive on the queue 34471943.&lt;BR /&gt;
49395|  main: number of bytes received: 63&lt;BR /&gt;
49395|  09:41:18 &lt;BR /&gt;
49395|  main: Found message format 1.00&lt;BR /&gt;
49395|  =&amp;gt;sv_msg2msgx_ent (tag_utils.c)&lt;BR /&gt;
49395|  =&amp;gt;svm_dprint (sv_message.c     10.4)&lt;BR /&gt;
49395|  svm_dprint: Message v1.00&lt;BR /&gt;
umsgnum =   00000000    org_pid =   00000000&lt;BR /&gt;
dest_pid =  00000000    timestamp_in =  1301204478&lt;BR /&gt;
msg_size =  00000007    msgtype =   00000022&lt;BR /&gt;
direction = 00000000    dev_proc_id =   00000000&lt;BR /&gt;
org_dev_qid =   34471943    49395|  BITS: 49395|&lt;BR /&gt;&lt;BR /&gt;
...................................................................................................&lt;BR /&gt;
0|  =&amp;gt;get_from_addldata (tag_utils.c)&lt;BR /&gt;
0|  get_from_addldata:Input dptr=0x0x600fffffffef6fc8 limit=0x0x600fffffffef6fc8&lt;BR /&gt;
0|  Tag 0xBD SVT_ACTION is not present in bpc_addldata&lt;BR /&gt;
0|  txn_needs_new_routing: return FALSE&lt;BR /&gt;
0|  =&amp;gt;COMMIT_WORK (db_login.pc)&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 20:08:07 GMT</pubDate>
    <dc:creator>DuXa</dc:creator>
    <dc:date>2020-09-28T20:08:07Z</dc:date>
    <item>
      <title>the beginning and end of the event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136556#M97847</link>
      <description>&lt;P&gt;Hello, i have logs with some event.  I want see only my event. How i can remove another information. My event bigins at:"main: number of bytes received: 489"  and finish at: "Send msg to queue *******" Could you help me in skype digilan007&lt;/P&gt;

&lt;P&gt;6|  set_buffer_mode: stderr is line-buffered&lt;BR /&gt;
6|  Opened txrout.out, Mar 27 at 09:38:00&lt;/P&gt;

&lt;P&gt;6|  #!# SVFE Ver. 2.2.7 build 20050624 #!#&lt;BR /&gt;
6|  =&amp;gt;COMMIT_WORK (db_login.pc)&lt;BR /&gt;
0|  &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Task with ID = 11 is waiting for the message to arrive on the queue 34471943.&lt;BR /&gt;
49395|  main: number of bytes received: 63&lt;BR /&gt;
49395|  09:41:18 &lt;BR /&gt;
49395|  main: Found message format 1.00&lt;BR /&gt;
49395|  =&amp;gt;sv_msg2msgx_ent (tag_utils.c)&lt;BR /&gt;
49395|  =&amp;gt;svm_dprint (sv_message.c     10.4)&lt;BR /&gt;
49395|  svm_dprint: Message v1.00&lt;BR /&gt;
umsgnum =   00000000    org_pid =   00000000&lt;BR /&gt;
dest_pid =  00000000    timestamp_in =  1301204478&lt;BR /&gt;
msg_size =  00000007    msgtype =   00000022&lt;BR /&gt;
direction = 00000000    dev_proc_id =   00000000&lt;BR /&gt;
org_dev_qid =   34471943    49395|  BITS: 49395|&lt;BR /&gt;&lt;BR /&gt;
...................................................................................................&lt;BR /&gt;
0|  =&amp;gt;get_from_addldata (tag_utils.c)&lt;BR /&gt;
0|  get_from_addldata:Input dptr=0x0x600fffffffef6fc8 limit=0x0x600fffffffef6fc8&lt;BR /&gt;
0|  Tag 0xBD SVT_ACTION is not present in bpc_addldata&lt;BR /&gt;
0|  txn_needs_new_routing: return FALSE&lt;BR /&gt;
0|  =&amp;gt;COMMIT_WORK (db_login.pc)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136556#M97847</guid>
      <dc:creator>DuXa</dc:creator>
      <dc:date>2020-09-28T20:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: the beginning and end of the event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136557#M97848</link>
      <description>&lt;P&gt;Which are all the information,you want to remove.Can u please be more specific on your query?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 05:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136557#M97848</guid>
      <dc:creator>jackson1990</dc:creator>
      <dc:date>2015-06-05T05:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: the beginning and end of the event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136558#M97849</link>
      <description>&lt;P&gt;Hi, your sample data does not correspond with the event delimiters you specify. (There is no line "Send message to queue..."). Also, this is the user forum, not an official support site - maybe someone will call you on skype, but you shouldn't count on it.&lt;/P&gt;

&lt;P&gt;In general, it would probably be good to study the documentation sections for props.conf, more specifically around the parameters for breaking the incoming data stream into events (BREAK_ONLY_BEFORE... MUST_NOT_BREAK...), and possibly also the docs on anonymizing data, which could be a means for removing the unwanted lines.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Indexmulti-lineevents" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Indexmulti-lineevents&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Anonymizedatausingconfigurationfiles" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Anonymizedatausingconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:08:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136558#M97849</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2020-09-28T20:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: the beginning and end of the event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136559#M97850</link>
      <description>&lt;P&gt;As Kristian said in the comment, you probably want to redefine the way you want splunk to parse your events.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Indexmulti-lineevents"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Indexmulti-lineevents&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then once you isolated the pieces : delete the useless events  (see nullQueue), or reformat them using (SEDCMD)&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Anonymizedatausingconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Anonymizedatausingconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2015 03:35:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/the-beginning-and-end-of-the-event/m-p/136559#M97850</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2015-06-14T03:35:04Z</dc:date>
    </item>
  </channel>
</rss>

