<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regex with Line break while pushing data into splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488161#M136388</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;

&lt;P&gt;Could you please help to parse this data while pushing this in source type data into splunk.&lt;/P&gt;

&lt;P&gt;Issue is if i am adding Event Break with Regex using this  }}(,) &lt;/P&gt;

&lt;P&gt;ROW1 getting converted into JSON but ROW2 is not able to convert due to its merging data (like in Row 2 there is 2 _time )&lt;/P&gt;

&lt;P&gt;Could anyone please help ?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Row 1&lt;/STRONG&gt;&lt;BR /&gt;
{"time":"2019-12-27T18:08:56.9035062Z","systemId":"03761897-51e8-4a4f-b1c7-01b5372fbece","macAddress":"000D3AF9BCB0","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/E63B08C3-D314-48D8-B10A-C58199BB78B1/RESOURCEGROUPS/AZUR-P-1-SOSG-RG-1/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/S-10.65.5.192-28-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":1,"flows":[{"rule":"UserRule_Deny_Outbound","flows":[{"mac":"000D3AF9BCB0","flowTuples":["1577470084,10.65.5.198,205.185.216"]}]}]}}&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Row 2&lt;/STRONG&gt;&lt;BR /&gt;
{"time":"2019-12-27T18:09:56.9504048Z","systemId":"03761897-51e8-4a4f-b1c7-01b5372fbece","macAddress":"000D3AF9BCB0","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/E63B08C3-D314-48D8-B10A-C58199BB78B1/RESOURCEGROUPS/AZUR-P-1-SOSG-RG-1/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/S-10.65.5.192-28-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":1,"flows":[{"rule":"UserRule_Deny_Outbound","flows":[{"mac":"000D3AF9BCB0","flowTuples":["1577470135,10.65.5.198,23.75.194.41,59094,80,T,O,D"]}]}]}}]}&lt;BR /&gt;
{"time":"2019-12-27T18:00:55.7627056Z","systemId":"a951027c-dc23-41a7-9973-77afcfa4bbfd","macAddress":"000D3A6D539B","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/E63B08C3-D314-48D8-B10A-C58199BB78B1/RESOURCEGROUPS/AZUR-P-1-SOSG-RG-1/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/S-10.65.5.48-28-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":1,"flows":[{"rule":"UserRule_Deny_Outbound","flows":[{"mac":"000D3A6D539B","flowTuples":["1577469594,10.65.5.53,10.65.5.68,59262,17472,T,O,D","1577469595,10.65.5.53,168.62.24.23,59254,443,T,O,D"]}]}]}}&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/279678-sourcetype.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 03:44:42 GMT</pubDate>
    <dc:creator>mailtosnsolutio</dc:creator>
    <dc:date>2020-09-30T03:44:42Z</dc:date>
    <item>
      <title>Regex with Line break while pushing data into splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488161#M136388</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;

&lt;P&gt;Could you please help to parse this data while pushing this in source type data into splunk.&lt;/P&gt;

&lt;P&gt;Issue is if i am adding Event Break with Regex using this  }}(,) &lt;/P&gt;

&lt;P&gt;ROW1 getting converted into JSON but ROW2 is not able to convert due to its merging data (like in Row 2 there is 2 _time )&lt;/P&gt;

&lt;P&gt;Could anyone please help ?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Row 1&lt;/STRONG&gt;&lt;BR /&gt;
{"time":"2019-12-27T18:08:56.9035062Z","systemId":"03761897-51e8-4a4f-b1c7-01b5372fbece","macAddress":"000D3AF9BCB0","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/E63B08C3-D314-48D8-B10A-C58199BB78B1/RESOURCEGROUPS/AZUR-P-1-SOSG-RG-1/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/S-10.65.5.192-28-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":1,"flows":[{"rule":"UserRule_Deny_Outbound","flows":[{"mac":"000D3AF9BCB0","flowTuples":["1577470084,10.65.5.198,205.185.216"]}]}]}}&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Row 2&lt;/STRONG&gt;&lt;BR /&gt;
{"time":"2019-12-27T18:09:56.9504048Z","systemId":"03761897-51e8-4a4f-b1c7-01b5372fbece","macAddress":"000D3AF9BCB0","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/E63B08C3-D314-48D8-B10A-C58199BB78B1/RESOURCEGROUPS/AZUR-P-1-SOSG-RG-1/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/S-10.65.5.192-28-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":1,"flows":[{"rule":"UserRule_Deny_Outbound","flows":[{"mac":"000D3AF9BCB0","flowTuples":["1577470135,10.65.5.198,23.75.194.41,59094,80,T,O,D"]}]}]}}]}&lt;BR /&gt;
{"time":"2019-12-27T18:00:55.7627056Z","systemId":"a951027c-dc23-41a7-9973-77afcfa4bbfd","macAddress":"000D3A6D539B","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/E63B08C3-D314-48D8-B10A-C58199BB78B1/RESOURCEGROUPS/AZUR-P-1-SOSG-RG-1/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/S-10.65.5.48-28-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":1,"flows":[{"rule":"UserRule_Deny_Outbound","flows":[{"mac":"000D3A6D539B","flowTuples":["1577469594,10.65.5.53,10.65.5.68,59262,17472,T,O,D","1577469595,10.65.5.53,168.62.24.23,59254,443,T,O,D"]}]}]}}&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/279678-sourcetype.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488161#M136388</guid>
      <dc:creator>mailtosnsolutio</dc:creator>
      <dc:date>2020-09-30T03:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Regex with Line break while pushing data into splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488162#M136389</link>
      <description>&lt;P&gt;Try &lt;CODE&gt;LINE_BREAKER = ([\r\n]+){"time"&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 21:06:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488162#M136389</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-16T21:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Regex with Line break while pushing data into splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488163#M136390</link>
      <description>&lt;P&gt;Sorry its not working&lt;/P&gt;

&lt;P&gt;actaully having issue of Row 2 Ending "]}]}]}} &amp;lt;------ This one creating issue&lt;BR /&gt;
as in Row 1 it have  ]}]}]}}&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 07:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-with-Line-break-while-pushing-data-into-splunk/m-p/488163#M136390</guid>
      <dc:creator>mailtosnsolutio</dc:creator>
      <dc:date>2020-01-17T07:59:56Z</dc:date>
    </item>
  </channel>
</rss>

