<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Confuguring events for AS400 logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216003#M98846</link>
    <description>&lt;P&gt;Hi...&lt;/P&gt;

&lt;P&gt;I have a AS400 syslog file. for which I am want to configure splunk to pick up the events at every 2 lines.&lt;BR /&gt;
Please advise which is the best way to do it &lt;/P&gt;

&lt;P&gt;Sample log &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;5761SS1 V6R1M0 080215                                   History Log                                                   Page  0001
MSGID    SEV MSG TYPE
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Start of the event&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;CPF1124  00  INFO         Job 252582/QTMHHTTP/QIWIRELESS started on 07/04/16 at 00:00:21 in subsystem QHTTPSVR in QHTTPSVR. Job ent
                  QIWIRELESS QTMHHTTP   252582 QWTPIIPP     0000 07/04/16 00:00:22.002029 QTMHHTTP
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;End of the Event&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;CPF1164  00  COMPLETION   Job 252582/QTMHHTTP/QIWIRELESS ended on 07/04/16 at 00:00:22; .034 seconds used; end code 0
                  QIWIRELESS QTMHHTTP   252582 QWTMCEOJ     0000 07/04/16 00:00:22.701533 QTMHHTTP
CPF1124  00  INFO         Job 252583/QPM400/Q1PDR started on 07/04/16 at 00:00:23 in subsystem QSYSWRK in QSYS. Job entered system
                  Q1PDR      QPM400     252583 QWTPIIPP     0000 07/04/16 00:00:23.286025 QPM400
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 09 Aug 2016 06:11:06 GMT</pubDate>
    <dc:creator>yasinmoha</dc:creator>
    <dc:date>2016-08-09T06:11:06Z</dc:date>
    <item>
      <title>Confuguring events for AS400 logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216003#M98846</link>
      <description>&lt;P&gt;Hi...&lt;/P&gt;

&lt;P&gt;I have a AS400 syslog file. for which I am want to configure splunk to pick up the events at every 2 lines.&lt;BR /&gt;
Please advise which is the best way to do it &lt;/P&gt;

&lt;P&gt;Sample log &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;5761SS1 V6R1M0 080215                                   History Log                                                   Page  0001
MSGID    SEV MSG TYPE
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Start of the event&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;CPF1124  00  INFO         Job 252582/QTMHHTTP/QIWIRELESS started on 07/04/16 at 00:00:21 in subsystem QHTTPSVR in QHTTPSVR. Job ent
                  QIWIRELESS QTMHHTTP   252582 QWTPIIPP     0000 07/04/16 00:00:22.002029 QTMHHTTP
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;End of the Event&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;CPF1164  00  COMPLETION   Job 252582/QTMHHTTP/QIWIRELESS ended on 07/04/16 at 00:00:22; .034 seconds used; end code 0
                  QIWIRELESS QTMHHTTP   252582 QWTMCEOJ     0000 07/04/16 00:00:22.701533 QTMHHTTP
CPF1124  00  INFO         Job 252583/QPM400/Q1PDR started on 07/04/16 at 00:00:23 in subsystem QSYSWRK in QSYS. Job entered system
                  Q1PDR      QPM400     252583 QWTPIIPP     0000 07/04/16 00:00:23.286025 QPM400
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Aug 2016 06:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216003#M98846</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-08-09T06:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Confuguring events for AS400 logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216004#M98847</link>
      <description>&lt;P&gt;I thought of adding the regex .&lt;EM&gt;\n.&lt;/EM&gt; in /opt/splunk/etc/system/local/props.conf but could not locate the file. &lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 08:10:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216004#M98847</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-08-09T08:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Confuguring events for AS400 logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216005#M98848</link>
      <description>&lt;P&gt;the question is bit not clear. may we know, some more info please..&lt;BR /&gt;
 1. from this above sample log msg, do you want to query this event ah?&lt;BR /&gt;
Start of the event&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;CPF1124 00 INFO Job 252582/QTMHHTTP/QIWIRELESS started on 07/04/16 at 00:00:21 in subsystem QHTTPSVR in QHTTPSVR. Job ent&lt;BR /&gt;
QIWIRELESS QTMHHTTP 252582 QWTPIIPP 0000 07/04/16 00:00:22.002029 QTMHHTTP &amp;lt;&amp;lt;&amp;lt;&amp;lt; &lt;BR /&gt;
End of the Event&lt;BR /&gt;
 2. the above sample log is a single event or multiple events? &lt;BR /&gt;
 3. from this sample log, can you tell us, how to find out the "start of the event" and "end of the event".. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 09 Aug 2016 08:48:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216005#M98848</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2016-08-09T08:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Confuguring events for AS400 logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216006#M98849</link>
      <description>&lt;P&gt;I have ingested this log in splunk but at some places it take 1 line as event and at some places it takes 2 or 3 lines as the event. &lt;BR /&gt;
An event spans over 2 lines so I am trying to create a single event for every two lines. In the UI I gave the regex .&lt;EM&gt;\n.&lt;/EM&gt; but it picks up 257 lines. &lt;BR /&gt;
Also I tried to edit $SPLUNK_HOME/etc/system/local/props.conf but could not locate this file. thinking of adding the &lt;/P&gt;

&lt;P&gt;SHOULD_LINEMERGE= true&lt;BR /&gt;
MUST_BREAK_AFTER = .&lt;EM&gt;\n.&lt;/EM&gt;&lt;BR /&gt;
MAX_EVENTS = 2&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Event 1&lt;/STRONG&gt; &lt;BR /&gt;
 5761SS1 V6R1M0 080215 History Log Page 0001&lt;BR /&gt;
MSGID SEV MSG TYPE&lt;BR /&gt;
&lt;STRONG&gt;Event 2&lt;/STRONG&gt; &lt;BR /&gt;
CPF1124 00 INFO Job 252582/QTMHHTTP/QIWIRELESS started on 07/04/16 at 00:00:21 in subsystem QHTTPSVR in QHTTPSVR. Job ent&lt;BR /&gt;
QIWIRELESS QTMHHTTP 252582 QWTPIIPP 0000 07/04/16 00:00:22.002029 QTMHHTTP&lt;BR /&gt;
&lt;STRONG&gt;Event 3&lt;/STRONG&gt;&lt;BR /&gt;
CPF1164 00 COMPLETION Job 252582/QTMHHTTP/QIWIRELESS ended on 07/04/16 at 00:00:22; .034 seconds used; end code 0&lt;BR /&gt;
QIWIRELESS QTMHHTTP 252582 QWTMCEOJ 0000 07/04/16 00:00:22.701533 QTMHHTTP&lt;BR /&gt;
&lt;STRONG&gt;Event 4&lt;/STRONG&gt;&lt;BR /&gt;
CPF1124 00 INFO Job 252583/QPM400/Q1PDR started on 07/04/16 at 00:00:23 in subsystem QSYSWRK in QSYS. Job entered system&lt;BR /&gt;
Q1PDR QPM400 252583 QWTPIIPP 0000 07/04/16 00:00:23.286025 QPM400&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216006#M98849</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2020-09-29T10:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Confuguring events for AS400 logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216007#M98850</link>
      <description>&lt;P&gt;Hi...&lt;/P&gt;

&lt;P&gt;I am trying to create a single event for every 2 lines of the log. When I ingest to splunk it some times take 1 or 2 or 3 lines as a single event. like below &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Event 1&lt;/STRONG&gt; &lt;BR /&gt;
 5761SS1 V6R1M0 080215 History Log Page 0001&lt;BR /&gt;
MSGID SEV MSG TYPE&lt;BR /&gt;
&lt;STRONG&gt;Event 2&lt;/STRONG&gt; &lt;BR /&gt;
CPF1124 00 INFO Job 252582/QTMHHTTP/QIWIRELESS started on 07/04/16 at 00:00:21 in subsystem QHTTPSVR in QHTTPSVR. Job ent&lt;BR /&gt;
QIWIRELESS QTMHHTTP 252582 QWTPIIPP 0000 07/04/16 00:00:22.002029 QTMHHTTP&lt;BR /&gt;
&lt;STRONG&gt;Event 3&lt;/STRONG&gt; &lt;BR /&gt;
CPF1164 00 COMPLETION Job 252582/QTMHHTTP/QIWIRELESS ended on 07/04/16 at 00:00:22; .034 seconds used; end code 0&lt;BR /&gt;
QIWIRELESS QTMHHTTP 252582 QWTMCEOJ 0000 07/04/16 00:00:22.701533 QTMHHTTP&lt;BR /&gt;
&lt;STRONG&gt;Event 4&lt;/STRONG&gt; &lt;BR /&gt;
CPF1124 00 INFO Job 252583/QPM400/Q1PDR started on 07/04/16 at 00:00:23 in subsystem QSYSWRK in QSYS. Job entered system&lt;BR /&gt;
Q1PDR QPM400 252583 QWTPIIPP 0000 07/04/16 00:00:23.286025 QPM400&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 12:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216007#M98850</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-08-09T12:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Confuguring events for AS400 logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216008#M98851</link>
      <description>&lt;P&gt;Made a few changes under the advanced tab while ingesting the data &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SHOULD_LINEMERGE=True
BREAK_ONLY_BEFORE=^\S
MAX_EVENTS=2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And then the event breaking got configured properly. &lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 20:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Confuguring-events-for-AS400-logs/m-p/216008#M98851</guid>
      <dc:creator>yasinmoha</dc:creator>
      <dc:date>2016-08-12T20:09:26Z</dc:date>
    </item>
  </channel>
</rss>

