<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How come changes in my XML unstructured file are not reflected when I select &amp;quot;BREAK_ONLY_BEFORE?&amp;quot; in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431326#M28428</link>
    <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/88201/need-help-with-event-breaking-in-xml-log-file.html"&gt;https://answers.splunk.com/answers/88201/need-help-with-event-breaking-in-xml-log-file.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;works with me.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Aug 2018 05:47:22 GMT</pubDate>
    <dc:creator>riqbal</dc:creator>
    <dc:date>2018-08-28T05:47:22Z</dc:date>
    <item>
      <title>How come changes in my XML unstructured file are not reflected when I select "BREAK_ONLY_BEFORE?"</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431323#M28425</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8" ?&amp;gt;&amp;lt;dataroot&amp;gt;&amp;lt;Interceptor&amp;gt;&amp;lt;AttackCoords&amp;gt;-80.33xxxxxxx22947&amp;lt;/AttackCoords&amp;gt;&amp;lt;Outcome&amp;gt;Interdiction&amp;lt;/Outcome&amp;gt;&amp;lt;Infiltrators&amp;gt;23&amp;lt;/Infiltrators&amp;gt;&amp;lt;Enforcer&amp;gt;Ironwood&amp;lt;/Enforcer&amp;gt;&amp;lt;ActionDate&amp;gt;2013-04-24&amp;lt;/ActionDate&amp;gt;&amp;lt;ActionTime&amp;gt;00:0xx:00&amp;lt;/ActionTime&amp;gt;&amp;lt;RecordNotes&amp;gt;&amp;lt;/RecordNotes&amp;gt;&amp;lt;NumEscaped&amp;gt;0&amp;lt;/NumEscaped&amp;gt;&amp;lt;LaunchCoords&amp;gt;-80.2xxxxxxxxxxxx475695&amp;lt;/LaunchCoords&amp;gt;&amp;lt;AttackVessel&amp;gt;Rustic&amp;lt;/AttackVessel&amp;gt;&amp;lt;/Interceptor&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;hi everyone&lt;BR /&gt;
I have one unstructured xml file.  the event supposed to be start from &lt;CODE&gt;"&amp;lt;Interceptor&amp;gt;"&lt;/CODE&gt;&lt;BR /&gt;
while uploading the file, I select BREAK_ONLY_BEFORE= but seems that changes are not reflecting &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[xyz  ]
SHOULD_LINEMERGE=true
NO_BINARY_CHECK=true
TIME_FORMAT=%Y-%m-%d
TIME_PREFIX=&amp;lt;ActionDate&amp;gt;
MAX_TIMESTAMP_LOOKAHEAD=100
BREAK_ONLY_BEFORE=&amp;lt;Interceptor&amp;gt; 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:03:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431323#M28425</guid>
      <dc:creator>riqbal</dc:creator>
      <dc:date>2020-09-29T21:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: How come changes in my XML unstructured file are not reflected when I select "BREAK_ONLY_BEFORE?"</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431324#M28426</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;It's regex format, try this : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  BREAK_ONLY_BEFORE = \&amp;lt;Interceptor\&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;3no&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 13:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431324#M28426</guid>
      <dc:creator>3no</dc:creator>
      <dc:date>2018-08-27T13:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: How come changes in my XML unstructured file are not reflected when I select "BREAK_ONLY_BEFORE?"</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431325#M28427</link>
      <description>&lt;P&gt;not working, the xml file is without breaks.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 05:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431325#M28427</guid>
      <dc:creator>riqbal</dc:creator>
      <dc:date>2018-08-28T05:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: How come changes in my XML unstructured file are not reflected when I select "BREAK_ONLY_BEFORE?"</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431326#M28428</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/88201/need-help-with-event-breaking-in-xml-log-file.html"&gt;https://answers.splunk.com/answers/88201/need-help-with-event-breaking-in-xml-log-file.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;works with me.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 05:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431326#M28428</guid>
      <dc:creator>riqbal</dc:creator>
      <dc:date>2018-08-28T05:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: How come changes in my XML unstructured file are not reflected when I select "BREAK_ONLY_BEFORE?"</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431327#M28429</link>
      <description>&lt;P&gt;@riqbal converted your comment to answer. Please accept to mark as answered. Do up vote the other answer that has helped.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 06:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431327#M28429</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-08-28T06:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: How come changes in my XML unstructured file are not reflected when I select "BREAK_ONLY_BEFORE?"</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431328#M28430</link>
      <description>&lt;P&gt;I was having the same problem, and the LINE_BREAKER solution posted above appears to solve my problem, but I wanted to understand why BREAK_ONLY_BEFORE didn't work. I made it work by inserting a newline into the XML. So riqbal's data would look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8" ?&amp;gt;&amp;lt;dataroot&amp;gt;
&amp;lt;Interceptor&amp;gt;&amp;lt;AttackCoords&amp;gt;-80.33xxxxxxx22947&amp;lt;/AttackCoords&amp;gt;&amp;lt;Outcome&amp;gt;Interdiction&amp;lt;/Outcome&amp;gt;&amp;lt;Infiltrators&amp;gt;23&amp;lt;/Infiltrators&amp;gt;&amp;lt;Enforcer&amp;gt;Ironwood&amp;lt;/Enforcer&amp;gt;&amp;lt;ActionDate&amp;gt;2013-04-24&amp;lt;/ActionDate&amp;gt;&amp;lt;ActionTime&amp;gt;00:0xx:00&amp;lt;/ActionTime&amp;gt;&amp;lt;RecordNotes&amp;gt;&amp;lt;/RecordNotes&amp;gt;&amp;lt;NumEscaped&amp;gt;0&amp;lt;/NumEscaped&amp;gt;&amp;lt;LaunchCoords&amp;gt;-80.2xxxxxxxxxxxx475695&amp;lt;/LaunchCoords&amp;gt;&amp;lt;AttackVessel&amp;gt;Rustic&amp;lt;/AttackVessel&amp;gt;&amp;lt;/Interceptor&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then I got exactly the result I wanted (events being identified by a specific XML tag).&lt;/P&gt;

&lt;P&gt;This result makes sense, because the functional description for BREAK_ONLY_BEFORE is "When set, Splunk software creates a new event only if it encounters &lt;EM&gt;a new  line&lt;/EM&gt; that matches the regular expression." (Emphasis added.) In riqbal's data, Splunk won't find "a new line" with &lt;CODE&gt;&amp;lt;Interceptor&amp;gt;&lt;/CODE&gt; in it, unless he has multi-line data and the string appears again in another line. Additionally, anything that is also in the line that is before the tag (e.g., closing tags for the previous event, which is my situation) will also be part of the next event.&lt;/P&gt;

&lt;P&gt;LINE_BREAKER seems to be the better solution, however, since no editing of the XML is needed. FYI, this line (edited to match the preceding example) in props.conf work for me:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINEBREAKER=([\r\n]*)\&amp;lt;Interceptor
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-come-changes-in-my-XML-unstructured-file-are-not-reflected/m-p/431328#M28430</guid>
      <dc:creator>cw15147</dc:creator>
      <dc:date>2020-09-30T00:40:23Z</dc:date>
    </item>
  </channel>
</rss>

