<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Line breaking help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Line-breaking-help/m-p/569824#M198604</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239221"&gt;@khaizercruz&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Line-breaking configurations should be done before indexing the logs. So, you need to put&lt;SPAN&gt;LINE_BREAKER in forwarder(s).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Oct 2021 04:42:17 GMT</pubDate>
    <dc:creator>manjunathmeti</dc:creator>
    <dc:date>2021-10-06T04:42:17Z</dc:date>
    <item>
      <title>Line breaking help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Line-breaking-help/m-p/569821#M198603</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Can anyone please help me with the line breaking. Multiple Security events are merged into a single event, putting a highlight on the the timestamp where the event should break.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Event below should be split into 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt; &lt;SPAN class="field-value"&gt;&lt;A title="claroty:cef" href="https://ccaauwprdap127:8000/en-US/app/search/search?q=search%20index%3Dclaroty%20%22Alert%2FHost%20Scan%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-7d%40h&amp;amp;latest=now&amp;amp;sid=1633484010.12080#" target="_blank" rel="noopener"&gt;claroty:cef&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;2021-10-02&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:37:17&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class="t"&gt;User.Info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.10.32.132&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Oct&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;04:37:17&lt;/SPAN&gt; &lt;SPAN class="t"&gt;server026&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CEF:0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;Claroty&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;CTD&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;4.3.1&lt;/SPAN&gt;|&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Alert/Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Scan&lt;/SPAN&gt;&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Scan&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;10&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;src=10.206.164.120&lt;/SPAN&gt; &lt;SPAN class="t"&gt;smac=2c:00:00:0f:9a:ad:73&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dmac=28:0000:61:f7:7e:c3&lt;/SPAN&gt; &lt;SPAN class="t"&gt;externalId=24459&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cat=Security/Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Scan&lt;/SPAN&gt; &lt;SPAN class="t"&gt;start=Oct&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:43:36&lt;/SPAN&gt; &lt;SPAN class="t"&gt;msg=ICMP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;scan:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Asset&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.5.164.10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sent&lt;/SPAN&gt; &lt;SPAN class="t"&gt;packets&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;different&lt;/SPAN&gt; &lt;SPAN class="t"&gt;IP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;destinations&lt;/SPAN&gt; &lt;SPAN class="t"&gt;deviceExternalId=INDO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CIBITUNG&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs1Label=SourceAssetType&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs1=Endpoint&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs3Label=SourceZone&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs3=Endpoint:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Other&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cccs4Label=DestZone&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs4=Endpoint:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;MQTT&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs6Label=CTDlink&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs6=&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;2021-10-02&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:37:17&lt;/SPAN&gt; &lt;/STRONG&gt;&lt;SPAN class="t"&gt;User.Info&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.10.32.132&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Oct&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;04:37:17&lt;/SPAN&gt; &lt;SPAN class="t"&gt;server026&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CEF:0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;Claroty&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;CTD&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;4.3.1&lt;/SPAN&gt;|&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Alert/Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Scan&lt;/SPAN&gt;&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Scan&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;10&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;src=10.206.163.251&lt;/SPAN&gt; &lt;SPAN class="t"&gt;smac=28:00:00:f7:7e:cb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;shost=DESKTOP-0C11AFV&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dmac=00:1b:1b:2c:12:1a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;externalId=24460&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cat=Security/Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Scan&lt;/SPAN&gt; &lt;SPAN class="t"&gt;start=Oct&lt;/SPAN&gt; &lt;SPAN class="t"&gt;02&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:43:42&lt;/SPAN&gt; &lt;SPAN class="t"&gt;msg=ICMP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;scan:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Asset&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.51.163.251&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sent&lt;/SPAN&gt; &lt;SPAN class="t"&gt;packets&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;different&lt;/SPAN&gt; &lt;SPAN class="t"&gt;IP&lt;/SPAN&gt; &lt;SPAN class="t"&gt;destinations&lt;/SPAN&gt; &lt;SPAN class="t"&gt;deviceExternalId=INDO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CIBITUNG&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs1Label=SourceAssetType&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs1=Endpoint&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs3Label=SourceZone&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs3=Endpoint:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Other&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cccs4Label=DestZone&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs4=PLC:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;S7&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs6Label=CTDlink&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cs6=&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Current props.conf in search head&lt;BR /&gt;&lt;BR /&gt;[claroty:cef]&lt;BR /&gt;LINE_BREAKER = ([\r\n]*)[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])(2[0-3]|[01][0-9]):[0-5][0-9]&lt;BR /&gt;BREAK_ONLY_BEFORE = ([\r\n]*)[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])(2[0-3]|[01][0-9]):[0-5][0-9]&lt;BR /&gt;REPORT-cs1 = claroty_cef_1&lt;BR /&gt;REPORT-cs2 = claroty_cef_2&lt;BR /&gt;REPORT-cs3 = claroty_cef_3&lt;BR /&gt;REPORT-cs4 = claroty_cef_4&lt;BR /&gt;REPORT-cs5 = claroty_cef_5&lt;BR /&gt;REPORT-cs6 = claroty_cef_6&lt;BR /&gt;REPORT-cs7 = claroty_cef_7&lt;BR /&gt;REPORT-cs8 = claroty_cef_8&lt;BR /&gt;REPORT-cs9 = claroty_cef_9&lt;BR /&gt;EXTRACT-msg = msg=(?&amp;lt;msg&amp;gt;.*?).x00$&lt;BR /&gt;EXTRACT-rt = rt=(?&amp;lt;rt&amp;gt;\w\w\w\s\d\d\s\d\d\d\d\s\d\d:\d\d:\d\d)&lt;BR /&gt;EXTRACT-alert = Alert\|(?&amp;lt;Alert&amp;gt;.+?)\|&lt;BR /&gt;EXTRACT-event = Event\|(?&amp;lt;Event&amp;gt;.+?)\|&lt;BR /&gt;FIELDALIAS-AssignedTo = ResolvedAs AS AssignedTo&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;P&gt;&lt;SPAN class="field-value"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Additional question&lt;BR /&gt;once we got the correct settings to props.conf and running search again will the data be the same?&lt;BR /&gt;or it will only work for the new events that will be ingested to splunk?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 06 Oct 2021 03:30:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Line-breaking-help/m-p/569821#M198603</guid>
      <dc:creator>khaizercruz</dc:creator>
      <dc:date>2021-10-06T03:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Line breaking help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Line-breaking-help/m-p/569824#M198604</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239221"&gt;@khaizercruz&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Line-breaking configurations should be done before indexing the logs. So, you need to put&lt;SPAN&gt;LINE_BREAKER in forwarder(s).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 04:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Line-breaking-help/m-p/569824#M198604</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-10-06T04:42:17Z</dc:date>
    </item>
  </channel>
</rss>

