<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event breaks in an XML-file on multiple tags in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130300#M7688</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Here in this answer you have mentioned  "^...the search term is at the beginning of the line".&lt;BR /&gt;
Is it really necessary to have that  field in the start.&lt;/P&gt;

&lt;P&gt;In my case it's without any spaces or new line.&lt;/P&gt;

&lt;P&gt;`&amp;lt; ?xml version="1.0" encoding="UTF-8"?&amp;gt;&amp;lt; Content&amp;gt;&amp;lt; Admin&amp;gt;&amp;lt; Disregard_1&amp;gt;[]&amp;lt; /Disregard_1&amp;gt;&amp;lt; Date_and_time&amp;gt;Mon Jan 13 22:44:53 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Domain&amp;gt;01&amp;lt; /Domain&amp;gt;&amp;lt; Disregard_4&amp;gt;18512&amp;lt; /Disregard_4&amp;gt;&amp;lt; Machine_name&amp;gt;Server1&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;12&amp;lt; /Usecase&amp;gt;&lt;BR /&gt;
&amp;lt; /Admin&amp;gt;&amp;lt; Order&amp;gt;&amp;lt; Disregard_1&amp;gt;[---]&amp;lt; /Disregard_1&amp;gt;&amp;lt; Date_and_time&amp;gt;Wed Jan 15 11:19:25 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Domain&amp;gt;02&amp;lt; /Domain&amp;gt;&amp;lt; Machine_name&amp;gt;Server2&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;06&amp;lt; /Usecase&amp;gt;&amp;lt; Actor&amp;gt;&amp;lt; Type_of_actor&amp;gt;USER&amp;lt; /Type_of_actor&amp;gt;&amp;lt; /Actor&amp;gt;&amp;lt; /Order&amp;gt;&amp;lt; Order&amp;gt;&amp;lt; Disregard_1&amp;gt;[---]&amp;lt; /Disregard_1&amp;lt; Date_and_time&amp;gt;Thu Jan 16 12:18:03 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Domain&amp;gt;02&amp;lt; /Domain&amp;gt;&amp;lt; Machine_name&amp;gt;Server2&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;06&amp;lt; /Usecase&amp;gt;&amp;lt; /Order&amp;gt;&amp;lt; Alerting&amp;gt;&amp;lt; Disregard_1&amp;gt;ab&amp;lt; /Disregard_1&amp;gt;&amp;lt; Date_and_time&amp;gt;Tue Jan 14 09:56:37 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Machine_name&amp;gt;Server3&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;01&amp;lt; /Usecase&amp;gt;&amp;lt; /Alerting&amp;gt;&amp;lt; /Content&amp;gt;&lt;/P&gt;

&lt;P&gt;So will it work?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 20:46:59 GMT</pubDate>
    <dc:creator>nasrinmulani</dc:creator>
    <dc:date>2020-09-29T20:46:59Z</dc:date>
    <item>
      <title>Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130295#M7683</link>
      <description>&lt;P&gt;I have an XML file with multiple tags I want to break on. Not all tags should cause a break, but only a subset.&lt;BR /&gt;
E.g. &lt;BR /&gt;
&amp;lt; Security&amp;gt; ... &amp;lt; /Security&amp;gt; should be an event&lt;BR /&gt;
&amp;lt; Admin&amp;gt; ... &amp;lt; /Admin&amp;gt; should be another event&lt;BR /&gt;
&amp;lt; Order&amp;gt; ... &amp;lt; /Order&amp;gt; should be another event&lt;/P&gt;

&lt;P&gt;I tried to break on a regex, but it did not work:&lt;BR /&gt;
"&amp;lt; Security&amp;gt;" | "&amp;lt; Admin&amp;gt;" | "&amp;lt; Order&amp;gt;" | "&amp;lt; Payment&amp;gt;"&lt;/P&gt;

&lt;P&gt;A bonus would be if the header was disregarded/not listed.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2014 13:20:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130295#M7683</guid>
      <dc:creator>ulrich_track</dc:creator>
      <dc:date>2014-09-18T13:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130296#M7684</link>
      <description>&lt;P&gt;Can you put your props and transforms configuration? Where are you placing your regex?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2014 15:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130296#M7684</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-09-18T15:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130297#M7685</link>
      <description>&lt;P&gt;I am putting the regex in Add data » Files &amp;amp; directories » Data preview in the field Specify a pattern or regex to break before ex: \d+foo\d[2,4], Start Of Event, ^***&lt;/P&gt;

&lt;P&gt;the props and transforms are untouched, yet.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 08:05:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130297#M7685</guid>
      <dc:creator>ulrich_track</dc:creator>
      <dc:date>2014-09-19T08:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130298#M7686</link>
      <description>&lt;P&gt;Here is a typical sample of this file (with adapted XML-Tags&lt;BR /&gt;
&amp;lt; ?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;
&amp;lt; Content&amp;gt;&lt;BR /&gt;
&amp;lt; Admin&amp;gt;&lt;BR /&gt;
&amp;lt; Disregard_1&amp;gt;[]&amp;lt; /Disregard_1&amp;gt;&lt;BR /&gt;
&amp;lt; Date_and_time&amp;gt;Mon Jan 13 22:44:53 MET 2014&amp;lt; /Date_and_time&amp;gt;&lt;BR /&gt;
&amp;lt; Domain&amp;gt;01&amp;lt; /Domain&amp;gt;&lt;BR /&gt;
&amp;lt; Disregard_4&amp;gt;18512&amp;lt; /Disregard_4&amp;gt;&lt;BR /&gt;
&amp;lt; Machine_name&amp;gt;Server1&amp;lt; /Machine_name&amp;gt;&lt;BR /&gt;
&amp;lt; Usecase&amp;gt;12&amp;lt; /Usecase&amp;gt;&lt;BR /&gt;
&amp;lt; /Admin&amp;gt;&lt;BR /&gt;
&amp;#12;&amp;lt; Order&amp;gt;&lt;BR /&gt;
&amp;lt; Disregard_1&amp;gt;[---]&amp;lt; /Disregard_1&amp;gt;&lt;BR /&gt;
&amp;lt; Date_and_time&amp;gt;Wed Jan 15 11:19:25 MET 2014&amp;lt; /Date_and_time&amp;gt;&lt;BR /&gt;
&amp;lt; Domain&amp;gt;02&amp;lt; /Domain&amp;gt;&lt;BR /&gt;
&amp;lt; Machine_name&amp;gt;Server2&amp;lt; /Machine_name&amp;gt;&lt;BR /&gt;
&amp;lt; Usecase&amp;gt;06&amp;lt; /Usecase&amp;gt;&lt;BR /&gt;
&amp;lt; Actor&amp;gt;&lt;BR /&gt;
&amp;lt; Type_of_actor&amp;gt;USER&amp;lt; /Type_of_actor&amp;gt;&lt;BR /&gt;
&amp;lt; /Actor&amp;gt;&lt;BR /&gt;
&amp;lt; /Order&amp;gt;&lt;BR /&gt;
&amp;lt; Order&amp;gt;&lt;BR /&gt;
&amp;lt; Disregard_1&amp;gt;[---]&amp;lt; /Disregard_1&amp;gt;&lt;BR /&gt;
&amp;lt; Date_and_time&amp;gt;Thu Jan 16 12:18:03 MET 2014&amp;lt; /Date_and_time&amp;gt;&lt;BR /&gt;
&amp;lt; Domain&amp;gt;02&amp;lt; /Domain&amp;gt;&lt;BR /&gt;
&amp;lt; Machine_name&amp;gt;Server2&amp;lt; /Machine_name&amp;gt;&lt;BR /&gt;
&amp;lt; Usecase&amp;gt;06&amp;lt; /Usecase&amp;gt;&lt;BR /&gt;
&amp;lt; /Order&amp;gt;&lt;BR /&gt;
&amp;lt; Alerting&amp;gt;&lt;BR /&gt;
&amp;lt; Disregard_1&amp;gt;ab&amp;lt; /Disregard_1&amp;gt;&lt;BR /&gt;
&amp;lt; Date_and_time&amp;gt;Tue Jan 14 09:56:37 MET 2014&amp;lt; /Date_and_time&amp;gt;&lt;BR /&gt;
&amp;lt; Machine_name&amp;gt;Server3&amp;lt; /Machine_name&amp;gt;&lt;BR /&gt;
&amp;lt; Usecase&amp;gt;01&amp;lt; /Usecase&amp;gt;&lt;BR /&gt;
&amp;lt; /Alerting&amp;gt;&lt;BR /&gt;
&amp;lt; /Content&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130298#M7686</guid>
      <dc:creator>ulrich_track</dc:creator>
      <dc:date>2020-09-28T17:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130299#M7687</link>
      <description>&lt;P&gt;I found it:&lt;BR /&gt;
You have to enter this string in the Regex-field of Data preview (please remove the blanks after the &amp;lt; sign, I added them only because otherwise this forum would not accept it)&lt;/P&gt;

&lt;P&gt;(?m)^(&amp;lt; Admin&amp;gt;)|(&amp;lt; Order&amp;gt;)|(&amp;lt; Security&amp;gt;)|(&amp;lt; Payment&amp;gt;)&lt;/P&gt;

&lt;P&gt;It says: &lt;BR /&gt;
(?m) ...go for multiline and do not stop at the first event you find&lt;BR /&gt;
^...the search term is at the beginning of the line&lt;BR /&gt;
()...a grouped search term&lt;BR /&gt;
&amp;lt; Admin&amp;gt;...(e.g.) search the exact phrase, case-sensitive&lt;/P&gt;

&lt;P&gt;|...logical OR statement&lt;/P&gt;

&lt;P&gt;or directly in the props.conf file:&lt;BR /&gt;
[&lt;EM&gt;NameOfTheSourcetype&lt;/EM&gt;]&lt;BR /&gt;
BREAK_ONLY_BEFORE = (?m)^(&amp;lt; Admin&amp;gt;)|(&amp;lt; Order&amp;gt;)|(&amp;lt; Security&amp;gt;)|(&amp;lt; Payment&amp;gt;)&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
TIME_PREFIX = &amp;lt; Date_and_time&amp;gt;&lt;BR /&gt;
pulldown_type = 1&lt;/P&gt;

&lt;P&gt;The TIME_PREFIX was added by me, because my timestamp was tagged this way. You can leave it out, because your files will probably be tagged differently.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130299#M7687</guid>
      <dc:creator>ulrich_track</dc:creator>
      <dc:date>2020-09-28T17:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130300#M7688</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Here in this answer you have mentioned  "^...the search term is at the beginning of the line".&lt;BR /&gt;
Is it really necessary to have that  field in the start.&lt;/P&gt;

&lt;P&gt;In my case it's without any spaces or new line.&lt;/P&gt;

&lt;P&gt;`&amp;lt; ?xml version="1.0" encoding="UTF-8"?&amp;gt;&amp;lt; Content&amp;gt;&amp;lt; Admin&amp;gt;&amp;lt; Disregard_1&amp;gt;[]&amp;lt; /Disregard_1&amp;gt;&amp;lt; Date_and_time&amp;gt;Mon Jan 13 22:44:53 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Domain&amp;gt;01&amp;lt; /Domain&amp;gt;&amp;lt; Disregard_4&amp;gt;18512&amp;lt; /Disregard_4&amp;gt;&amp;lt; Machine_name&amp;gt;Server1&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;12&amp;lt; /Usecase&amp;gt;&lt;BR /&gt;
&amp;lt; /Admin&amp;gt;&amp;lt; Order&amp;gt;&amp;lt; Disregard_1&amp;gt;[---]&amp;lt; /Disregard_1&amp;gt;&amp;lt; Date_and_time&amp;gt;Wed Jan 15 11:19:25 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Domain&amp;gt;02&amp;lt; /Domain&amp;gt;&amp;lt; Machine_name&amp;gt;Server2&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;06&amp;lt; /Usecase&amp;gt;&amp;lt; Actor&amp;gt;&amp;lt; Type_of_actor&amp;gt;USER&amp;lt; /Type_of_actor&amp;gt;&amp;lt; /Actor&amp;gt;&amp;lt; /Order&amp;gt;&amp;lt; Order&amp;gt;&amp;lt; Disregard_1&amp;gt;[---]&amp;lt; /Disregard_1&amp;lt; Date_and_time&amp;gt;Thu Jan 16 12:18:03 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Domain&amp;gt;02&amp;lt; /Domain&amp;gt;&amp;lt; Machine_name&amp;gt;Server2&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;06&amp;lt; /Usecase&amp;gt;&amp;lt; /Order&amp;gt;&amp;lt; Alerting&amp;gt;&amp;lt; Disregard_1&amp;gt;ab&amp;lt; /Disregard_1&amp;gt;&amp;lt; Date_and_time&amp;gt;Tue Jan 14 09:56:37 MET 2014&amp;lt; /Date_and_time&amp;gt;&amp;lt; Machine_name&amp;gt;Server3&amp;lt; /Machine_name&amp;gt;&amp;lt; Usecase&amp;gt;01&amp;lt; /Usecase&amp;gt;&amp;lt; /Alerting&amp;gt;&amp;lt; /Content&amp;gt;&lt;/P&gt;

&lt;P&gt;So will it work?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:46:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130300#M7688</guid>
      <dc:creator>nasrinmulani</dc:creator>
      <dc:date>2020-09-29T20:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Event breaks in an XML-file on multiple tags</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130301#M7689</link>
      <description>&lt;P&gt;@nasrinmulani This thread is nearly 4 years old with an accepted answer so you're unlikely to get many responses.  I suggest you post a new question describing your problem.  Reference this answer if you wish.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 13:56:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Event-breaks-in-an-XML-file-on-multiple-tags/m-p/130301#M7689</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-08-02T13:56:52Z</dc:date>
    </item>
  </channel>
</rss>

