<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are my multi-line events getting split? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428545#M174159</link>
    <description>&lt;P&gt;That's weird, I tried both ways on my local based on your sample snippet in your question...&lt;BR /&gt;
1. having splunk do the line-breaking..etc., it's working &lt;BR /&gt;
2. adding props.conf, above props are working for me&lt;BR /&gt;
Can you check if any other configs are overriding your extractions...&lt;BR /&gt;
./splunk cmd btool props list --debug [sourcetype]&lt;/P&gt;</description>
    <pubDate>Tue, 11 Dec 2018 22:18:25 GMT</pubDate>
    <dc:creator>prakash007</dc:creator>
    <dc:date>2018-12-11T22:18:25Z</dc:date>
    <item>
      <title>Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428542#M174156</link>
      <description>&lt;P&gt;I am trying to prevent my multi-line events from being broken into individual rows. My logs are similar to this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-12-11 09:13:30.1832|170|DEBUG|Timer.MyTimerCallback =&amp;gt; ScheduledEventManager.CheckForScheduledEvents =&amp;gt; ScheduledEventManager.FireScheduledEvents|** 1 events processed in 0 seconds|
2018-12-11 09:16:22.1177|94|WARN|InternalDispatcher`1.Dispatch =&amp;gt; LoggingInterceptor.ReaderExecuted =&amp;gt; LoggingInterceptor.StopStopwatch|SQL Time Limit Exceeded!  
Query took 3122 ms, exceeding 3000 ms limit.  
SELECT 
    [UnionAll5].[PatientResponseId] AS [C1], 
    [UnionAll5].[PatientResponseId1] AS [C2], 
    [UnionAll5].[PatientResponseId2] AS [C3],
2018-12-11 09:16:30.1853|27|DEBUG|RuntimeMethodInfo.UnsafeInvokeInternal =&amp;gt; RuntimeMethodHandle.InvokeMethod =&amp;gt; EventManager.NotifySubscribers|NotifySubscribers Vivify.Platform.Events.PatientAlertDelayedEvent, inBackground False|
2018-12-11 09:16:30.1853|27|INFO|&amp;lt;&amp;gt;c__DisplayClass5_0`1.&amp;lt;NotifySubscribers&amp;gt;b__0 =&amp;gt; EventManager.NotifySubscriber =&amp;gt; EmailNotificationHandler.OnNext|Handle DelayedNotification: 1023|
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is my props.conf: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Log]
NO_BINARY_CHECK = true
category = Custom
description = CGP Application Logs
pulldown_type = 1
FIELD_DELIMITER = |
FIELD_NAMES = Timestamp,Thread,Level,Stack,Info,AddInfo
INDEXED_EXTRACTIONS = psv
disabled = false
SHOULD_LINEMERGE = false
TRUNCATE = 0
MAX_EVENTS = 40000
LINE_BREAKER = ([\r\n]+)([0-9]{4}-[0-9]{2}-[0-9]{2}) ([0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{4})
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The query that is getting split is actually much longer (~1600 lines).&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 20:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428542#M174156</guid>
      <dc:creator>tilbins</dc:creator>
      <dc:date>2018-12-11T20:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428543#M174157</link>
      <description>&lt;P&gt;hope this should work...MAX_EVENTS works only when SHOULD_LINEMERGE = true according to the docs..&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.0/Admin/Propsconf#Line_breaking" target="_blank"&gt;props.conf&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Log]
SHOULD_LINEMERGE = true
NO_BINARY_CHECK = true
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N
TIME_PREFIX = ^
MAX_TIMESTAMP_LOOKAHEAD = 25
BREAK_ONLY_BEFORE = \d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\.\d{4}
FIELD_DELIMITER = |
FIELD_NAMES = Timestamp,Thread,Level,Stack,Info,AddInfo
INDEXED_EXTRACTIONS = psv
MAX_EVENTS = 99999
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428543#M174157</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2020-09-29T22:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428544#M174158</link>
      <description>&lt;P&gt;Gave that a try and the multi-line events are still being broken into individual rows.  I have played around pretty extensively with the props.conf trying different variations.&lt;/P&gt;

&lt;P&gt;Even events like the following are getting broken into individual lines:&lt;BR /&gt;
    2018-12-11 01:01:42.2688|10|ERROR|&lt;EXECUTEEXCEPTIONFILTERASYNCCORE&gt;d_&lt;EM&gt;0.MoveNext =&amp;gt; ExceptionFilterAttribute.OnExceptionAsync =&amp;gt; ExceptionHandlerFilterAttribute.OnException|Exception Caught|System.OperationCanceledException: The operation was canceled.&lt;BR /&gt;
       at System.Threading.CancellationToken.ThrowOperationCanceledException()&lt;BR /&gt;
       at System.Web.Http.Filters.ActionFilterAttribute.&lt;CALLONACTIONEXECUTEDASYNC&gt;d&lt;/CALLONACTIONEXECUTEDASYNC&gt;&lt;/EM&gt;&lt;EM&gt;5.MoveNext()&lt;BR /&gt;
    --- End of stack trace from previous location where exception was thrown ---&lt;BR /&gt;
       at System.Runtime.ExceptionServices.ExceptionDispatchInfo.Throw()&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)&lt;BR /&gt;
       at System.Web.Http.Filters.ActionFilterAttribute.&lt;EXECUTEACTIONFILTERASYNCCORE&gt;d&lt;/EXECUTEACTIONFILTERASYNCCORE&gt;&lt;/EM&gt;&lt;EM&gt;0.MoveNext()&lt;BR /&gt;
    --- End of stack trace from previous location where exception was thrown ---&lt;BR /&gt;
       at System.Runtime.ExceptionServices.ExceptionDispatchInfo.Throw()&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)&lt;BR /&gt;
       at System.Web.Http.Controllers.ActionFilterResult.&lt;EXECUTEASYNC&gt;d&lt;/EXECUTEASYNC&gt;&lt;/EM&gt;&lt;EM&gt;2.MoveNext()&lt;BR /&gt;
    --- End of stack trace from previous location where exception was thrown ---&lt;BR /&gt;
       at System.Runtime.ExceptionServices.ExceptionDispatchInfo.Throw()&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)&lt;BR /&gt;
       at System.Web.Http.Filters.AuthorizationFilterAttribute.&lt;EXECUTEAUTHORIZATIONFILTERASYNCCORE&gt;d&lt;/EXECUTEAUTHORIZATIONFILTERASYNCCORE&gt;&lt;/EM&gt;&lt;EM&gt;2.MoveNext()&lt;BR /&gt;
    --- End of stack trace from previous location where exception was thrown ---&lt;BR /&gt;
       at System.Runtime.ExceptionServices.ExceptionDispatchInfo.Throw()&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)&lt;BR /&gt;
       at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)&lt;BR /&gt;
       at System.Web.Http.Controllers.ExceptionFilterResult.&lt;EXECUTEASYNC&gt;d&lt;/EXECUTEASYNC&gt;&lt;/EM&gt;_0.MoveNext()&lt;/EXECUTEEXCEPTIONFILTERASYNCCORE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428544#M174158</guid>
      <dc:creator>tilbins</dc:creator>
      <dc:date>2020-09-29T22:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428545#M174159</link>
      <description>&lt;P&gt;That's weird, I tried both ways on my local based on your sample snippet in your question...&lt;BR /&gt;
1. having splunk do the line-breaking..etc., it's working &lt;BR /&gt;
2. adding props.conf, above props are working for me&lt;BR /&gt;
Can you check if any other configs are overriding your extractions...&lt;BR /&gt;
./splunk cmd btool props list --debug [sourcetype]&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 22:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428545#M174159</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-11T22:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428546#M174160</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/153030"&gt;@tilbins&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;Check out &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Configureeventlinebreaking" target="_blank"&gt;Configure event line breaking&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;The default behavior of Splunk is to 1) split lines based on newlines and carriage returns and then 2) merge the lines (if SHOULD_LINEMERGE=true) in events when Splunk encounters a date (BREAK_ONLY_BEFORE_DATE=true by default).&lt;/P&gt;

&lt;P&gt;You are doing it differently by 1) splitting lines based on when Splunk encounters a date and then 2) not line merging. This is a different approach but can also work.&lt;/P&gt;

&lt;P&gt;In your case I favor the first approach. When I upload your file in Settings / Add Data / Upload and set SHOULD_LINEMERGE=true then Splunk is already doing a fine job. (However, I recommend to set the time format manually instead of letting Splunk guess it.) Also, don't forget to set MAX_EVENTS.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/259624-add-data.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428546#M174160</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2020-09-29T22:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428547#M174161</link>
      <description>&lt;P&gt;I started over from scratch and implemented it to these specifications.  Here's what my props.conf looks like now:&lt;BR /&gt;
    DATETIME_CONFIG = &lt;BR /&gt;
    NO_BINARY_CHECK = true&lt;BR /&gt;
    TIME_FORMAT = %Y-%m-%d %H:%M:%S.%4N&lt;BR /&gt;
    TZ = America/Chicago&lt;BR /&gt;
    category = Custom&lt;BR /&gt;
    pulldown_type = 1&lt;BR /&gt;
    MAX_EVENTS = 2000&lt;BR /&gt;
    disabled = false&lt;/P&gt;

&lt;P&gt;I still need to figure out the parsing, but my events are all back together now.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428547#M174161</guid>
      <dc:creator>tilbins</dc:creator>
      <dc:date>2020-09-29T22:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my multi-line events getting split?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428548#M174162</link>
      <description>&lt;P&gt;As a follow-up, used the transform.conf to setup the "|" delimiter:&lt;/P&gt;

&lt;P&gt;DELIMS = "|"&lt;BR /&gt;
FIELDS = TimeStamp,Thread,Level,Stack,Info,AddInfo&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 15:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-multi-line-events-getting-split/m-p/428548#M174162</guid>
      <dc:creator>tilbins</dc:creator>
      <dc:date>2018-12-12T15:36:22Z</dc:date>
    </item>
  </channel>
</rss>

