<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I break into multiple events just by space? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304513#M165646</link>
    <description>&lt;P&gt;Then your parsing settings need to go on the indexer as the UF does not do any event parsing.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 01:47:55 GMT</pubDate>
    <dc:creator>s2_splunk</dc:creator>
    <dc:date>2017-10-13T01:47:55Z</dc:date>
    <item>
      <title>How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304508#M165641</link>
      <description>&lt;P&gt;I want the one event in the picture to be broken into many events with the spaces in between. How do I do so with props.conf ?&lt;/P&gt;

&lt;P&gt;Heres what i tried in my props.conf i tried "LINE_BREAKER = \s" and "LINE_BREAKER = [\s]"&lt;BR /&gt;
[daemontest]&lt;BR /&gt;
LINE_BREAKER = ([\s]+)&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/216802-one-event.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:13:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304508#M165641</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2020-09-29T16:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304509#M165642</link>
      <description>&lt;P&gt;"LINE_BREAKER = ([\s]+)" with "SHOULD_LINEMERGE=false" should work, and it works for me after mocking up a similar example and using the preview feature of "Add Data".&lt;/P&gt;

&lt;P&gt;Are you sure those settings are being applied, i.e. are you restarting/refreshing Splunk after editing props.conf?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304509#M165642</guid>
      <dc:creator>jhigginsmq</dc:creator>
      <dc:date>2020-09-29T16:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304510#M165643</link>
      <description>&lt;P&gt;Are you configuring props.conf on the splunk instance that parses your event stream? That would be either your indexer, or a heavy forwarder you may have in your data ingest path.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 18:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304510#M165643</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-12T18:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304511#M165644</link>
      <description>&lt;P&gt;I am using universal forwarder &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 01:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304511#M165644</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2017-10-13T01:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304512#M165645</link>
      <description>&lt;P&gt;Yes i've restart everytime i finished editing props.conf&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 01:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304512#M165645</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2017-10-13T01:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304513#M165646</link>
      <description>&lt;P&gt;Then your parsing settings need to go on the indexer as the UF does not do any event parsing.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 01:47:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304513#M165646</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-13T01:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304514#M165647</link>
      <description>&lt;P&gt;See above, these settings have no effect on the UF, they need to go on the indexer, which is where the event parsing happens.&lt;BR /&gt;
All the forwarder sees are 64KB chunks of data read from a monitored file or received on a network input.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 01:49:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304514#M165647</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-13T01:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I break into multiple events just by space?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304515#M165648</link>
      <description>&lt;P&gt;This has been fixed by adding the parameter "BREAK_ONLY_BEFORE=\s"&lt;/P&gt;

&lt;P&gt;[daemontest]&lt;BR /&gt;
LINE_BREAKER = ([\s]+)&lt;BR /&gt;
BREAK_ONLY_BEFORE =\s&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;/P&gt;

&lt;P&gt;Above is my parameters used just by splitting events with space.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-break-into-multiple-events-just-by-space/m-p/304515#M165648</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2020-09-29T16:14:40Z</dc:date>
    </item>
  </channel>
</rss>

