<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can i break multiple lines of a log ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85518#M21857</link>
    <description>&lt;P&gt;How can i break this lines ?&lt;/P&gt;

&lt;P&gt;I used this regex but i can't obtain multiple data of each event with lot uid:&lt;/P&gt;

&lt;P&gt;Regex:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
[ldif]&lt;BR /&gt;
EXTRACT-ldifid = uniqueMember:\suid=(?&lt;LDIFID&gt;[^\,]+)&lt;/LDIFID&gt;&lt;/P&gt;

&lt;P&gt;uniqueMember: uid=b072psre,ou=people,o=b072,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044ghna,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044aaqu,ou=People,o=B044,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044mgcr,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044aasa,ou=People,o=B044,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044ogre,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044ggre,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b132mdga,ou=people,o=b132,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b830gosa,ou=People,o=B830,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b132vhga,ou=People,o=B132,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;/P&gt;

&lt;P&gt;Show all 242 lines&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
• host=ldif-locales&lt;BR /&gt;&lt;BR /&gt;
• source=OperadoresLocales.ldif&lt;BR /&gt;&lt;BR /&gt;
• sourcetype=ldif&lt;BR /&gt;&lt;BR /&gt;
• uid=b072psre&lt;BR /&gt;&lt;BR /&gt;
• ldifid=b072psre&lt;/P&gt;

&lt;P&gt;I want extract the values of the consecutive rows, then i can make a top of "uid"s, Splunk only returns one "uid" for each log.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jan 2013 18:49:54 GMT</pubDate>
    <dc:creator>nettrigger</dc:creator>
    <dc:date>2013-01-11T18:49:54Z</dc:date>
    <item>
      <title>How can i break multiple lines of a log ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85518#M21857</link>
      <description>&lt;P&gt;How can i break this lines ?&lt;/P&gt;

&lt;P&gt;I used this regex but i can't obtain multiple data of each event with lot uid:&lt;/P&gt;

&lt;P&gt;Regex:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
[ldif]&lt;BR /&gt;
EXTRACT-ldifid = uniqueMember:\suid=(?&lt;LDIFID&gt;[^\,]+)&lt;/LDIFID&gt;&lt;/P&gt;

&lt;P&gt;uniqueMember: uid=b072psre,ou=people,o=b072,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044ghna,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044aaqu,ou=People,o=B044,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044mgcr,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044aasa,ou=People,o=B044,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044ogre,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b044ggre,ou=people,o=b044,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b132mdga,ou=people,o=b132,o=nacionales,o=bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b830gosa,ou=People,o=B830,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;BR /&gt;
uniqueMember: uid=b132vhga,ou=People,o=B132,o=Nacionales,o=Bancos,o=clientes,o=prosa.com.mx,o=isp&lt;/P&gt;

&lt;P&gt;Show all 242 lines&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
• host=ldif-locales&lt;BR /&gt;&lt;BR /&gt;
• source=OperadoresLocales.ldif&lt;BR /&gt;&lt;BR /&gt;
• sourcetype=ldif&lt;BR /&gt;&lt;BR /&gt;
• uid=b072psre&lt;BR /&gt;&lt;BR /&gt;
• ldifid=b072psre&lt;/P&gt;

&lt;P&gt;I want extract the values of the consecutive rows, then i can make a top of "uid"s, Splunk only returns one "uid" for each log.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 18:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85518#M21857</guid>
      <dc:creator>nettrigger</dc:creator>
      <dc:date>2013-01-11T18:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can i break multiple lines of a log ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85519#M21858</link>
      <description>&lt;P&gt;You need to add the directive &lt;CODE&gt;MV_ADD = true&lt;/CODE&gt; in props.conf. By default Splunk will just extract one value and then stop - but if you specify &lt;CODE&gt;MV_ADD = true&lt;/CODE&gt; it will continue matching and create a multivalued field holding all values.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 19:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85519#M21858</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-11T19:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can i break multiple lines of a log ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85520#M21859</link>
      <description>&lt;P&gt;Thank you ! The lines is broken now ! But i don't understand why some lines is together yet.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 19:13:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-break-multiple-lines-of-a-log/m-p/85520#M21859</guid>
      <dc:creator>nettrigger</dc:creator>
      <dc:date>2013-01-22T19:13:06Z</dc:date>
    </item>
  </channel>
</rss>

