<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I break this two events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251976#M189328</link>
    <description>&lt;P&gt;Hello!!! &lt;/P&gt;

&lt;P&gt;Can you help me to break this two events, they must separated with this expression &lt;/P&gt;

&lt;H2&gt;WORD WORD WORD&lt;/H2&gt;

&lt;P&gt;We have this two events, so please use them as an example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SUBPROCESS Process Termination
------------------------------
Username:          ZZZZ              UIC:               [1,4]
Account:           WWWWWW            Finish time:       29-OCT-2015 00:00:09.15
Process ID:        DDDDDDDD          Start time:        29-OCT-2015 00:00:09.14
Owner ID:          AAAAAAAA          Elapsed time:                0 00:00:00.01
Terminal name:                       Processor time:              0 00:00:00.02
Remote node addr:                    Priority:          4
Remote node name:                    Privilege &amp;lt;31-00&amp;gt;: FFFFFFFF
Remote ID:                           Privilege &amp;lt;63-32&amp;gt;: FFFFFFFF
Remote full name:
Posix UID:         -2                Posix GID:         -2 (%XFFFFFFFE)
Queue entry:                         Final status code: 00000001
Queue name:
Job name:
Final status text: %SYSTEM-S-NORMAL, normal successful completion
Page faults:               81        Direct IO:                  5
Page fault reads:          21        Buffered IO:              120
Peak working set:        1616        Volumes mounted:            0
Peak page file:        171680        Images executed:            3
&amp;#12;
NETWORK Process Termination
---------------------------
Username:          XXXX              UIC:               [1,4]
Account:           XDXDXD            Finish time:       29-OCT-2015 00:00:09.16
Process ID:        YYYYYYYY          Start time:        29-OCT-2015 00:00:05.82
Owner ID:                            Elapsed time:                0 00:00:03.34
Terminal name:                       Processor time:              0 00:00:00.16
Remote node addr:                    Priority:          4
Remote node name:                    Privilege &amp;lt;31-00&amp;gt;: FFFFFFFF
Remote ID:         NRPE              Privilege &amp;lt;63-32&amp;gt;: FFFFFFFF
Remote full name:  161.131.194.38
Posix UID:         -2                Posix GID:         -2 (%XFFFFFFFE)
Queue entry:                         Final status code: 00000001
Queue name:
Job name:
Final status text: %SYSTEM-S-NORMAL, normal successful completion
Page faults:              408        Direct IO:                119
Page fault reads:         108        Buffered IO:              793
Peak working set:        6912        Volumes mounted:            0
Peak page file:        176720        Images executed:            7
&amp;#12;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks for your help!!!&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2015 20:08:05 GMT</pubDate>
    <dc:creator>prianticoy</dc:creator>
    <dc:date>2015-11-26T20:08:05Z</dc:date>
    <item>
      <title>How can I break this two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251976#M189328</link>
      <description>&lt;P&gt;Hello!!! &lt;/P&gt;

&lt;P&gt;Can you help me to break this two events, they must separated with this expression &lt;/P&gt;

&lt;H2&gt;WORD WORD WORD&lt;/H2&gt;

&lt;P&gt;We have this two events, so please use them as an example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SUBPROCESS Process Termination
------------------------------
Username:          ZZZZ              UIC:               [1,4]
Account:           WWWWWW            Finish time:       29-OCT-2015 00:00:09.15
Process ID:        DDDDDDDD          Start time:        29-OCT-2015 00:00:09.14
Owner ID:          AAAAAAAA          Elapsed time:                0 00:00:00.01
Terminal name:                       Processor time:              0 00:00:00.02
Remote node addr:                    Priority:          4
Remote node name:                    Privilege &amp;lt;31-00&amp;gt;: FFFFFFFF
Remote ID:                           Privilege &amp;lt;63-32&amp;gt;: FFFFFFFF
Remote full name:
Posix UID:         -2                Posix GID:         -2 (%XFFFFFFFE)
Queue entry:                         Final status code: 00000001
Queue name:
Job name:
Final status text: %SYSTEM-S-NORMAL, normal successful completion
Page faults:               81        Direct IO:                  5
Page fault reads:          21        Buffered IO:              120
Peak working set:        1616        Volumes mounted:            0
Peak page file:        171680        Images executed:            3
&amp;#12;
NETWORK Process Termination
---------------------------
Username:          XXXX              UIC:               [1,4]
Account:           XDXDXD            Finish time:       29-OCT-2015 00:00:09.16
Process ID:        YYYYYYYY          Start time:        29-OCT-2015 00:00:05.82
Owner ID:                            Elapsed time:                0 00:00:03.34
Terminal name:                       Processor time:              0 00:00:00.16
Remote node addr:                    Priority:          4
Remote node name:                    Privilege &amp;lt;31-00&amp;gt;: FFFFFFFF
Remote ID:         NRPE              Privilege &amp;lt;63-32&amp;gt;: FFFFFFFF
Remote full name:  161.131.194.38
Posix UID:         -2                Posix GID:         -2 (%XFFFFFFFE)
Queue entry:                         Final status code: 00000001
Queue name:
Job name:
Final status text: %SYSTEM-S-NORMAL, normal successful completion
Page faults:              408        Direct IO:                119
Page fault reads:         108        Buffered IO:              793
Peak working set:        6912        Volumes mounted:            0
Peak page file:        176720        Images executed:            7
&amp;#12;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks for your help!!!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 20:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251976#M189328</guid>
      <dc:creator>prianticoy</dc:creator>
      <dc:date>2015-11-26T20:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: How can I break this two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251977#M189329</link>
      <description>&lt;P&gt;If you split the time index･･･&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  [your_events]
  BREAK_ONLY_BEFORE = NETWORK Process Termination
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you split the search statement･･･&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  (your search)|eval wk_raw=replace(_raw,"NETWORK Process Termination","[break]NETWORK Process Termination") |makemv delim="[break]" wk_raw | mvexpand wk_raw|eval _raw=wk_raw
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 Nov 2015 06:06:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251977#M189329</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2015-11-27T06:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: How can I break this two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251978#M189330</link>
      <description>&lt;P&gt;Thanks for your answer, but I can't use the complete phrase as line breaker because the words are changing during the different events. I already work in the props file  with this command: BREAK_ONLY_BEFORE and a regular expression, and didn't work...&lt;/P&gt;

&lt;P&gt;I can't split it in the search statement because I'm trying to define the sourcetype...&lt;/P&gt;

&lt;P&gt;Do you have another idea?&lt;/P&gt;

&lt;P&gt;Thanks again!!!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:02:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-break-this-two-events/m-p/251978#M189330</guid>
      <dc:creator>prianticoy</dc:creator>
      <dc:date>2020-09-29T08:02:39Z</dc:date>
    </item>
  </channel>
</rss>

