<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to fix issue with parsing events (log files)? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642634#M222587</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I have issues with parsing events, multiple events/records (raw data) are within the same event. Sample data and my props configuration file are giving below. How help will be highly appreciated. Thank you so much in advance for your help:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sample Events&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chainData.PremiseMessageChainTracer&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;beginChain&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Message&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;chain&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;#5:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Begin&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C369823455-7843-44D7-89E3-SAB21BF361F24F&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;Request&lt;/SPAN&gt;]&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chainData.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C369823655-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C369823-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C3698sdss23-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;attached-email-body.txt&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;11&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessorr$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C3698saaa23-7843-44D7-89E3-B21BF361566F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;10&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C3698sdaa23-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[[&lt;SPAN class=""&gt;EXT&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;LibraryLink&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;Library&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Link&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;the&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Day&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;2023-05-09_attached-email-body&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.imagepreclassifier.ImagePreclassifierManager&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;applyPrefiltersOnImages&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;INFO:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Skipping&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;component:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;unknown&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;image&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;filtering&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;as&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;required&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;component.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;PROPS.CONF&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;[auditrdata]&lt;/P&gt;
&lt;P class=""&gt;SHOULD_LINEMERGE=false&lt;/P&gt;
&lt;P class=""&gt;LINE_BREAKER=([\r\n]+)\w+\s\d{2},\s\d{4}&lt;/P&gt;
&lt;P class=""&gt;NO_BINARY_CHECK=true&lt;/P&gt;
&lt;P class=""&gt;CHARSET=UTF-8&lt;/P&gt;
&lt;P class=""&gt;disabled=false&lt;/P&gt;
&lt;P class=""&gt;TIME_PREFIX=^&lt;/P&gt;
&lt;P class=""&gt;TIME_FORMAT=%b %d, %Y %H:%M:%S&lt;/P&gt;
&lt;P class=""&gt;MAX_TIMESTAMP_LOOKAHEAD=30&lt;/P&gt;
&lt;P class=""&gt;TRUNCATE=5000&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 16:24:00 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2023-05-09T16:24:00Z</dc:date>
    <item>
      <title>How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642634#M222587</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I have issues with parsing events, multiple events/records (raw data) are within the same event. Sample data and my props configuration file are giving below. How help will be highly appreciated. Thank you so much in advance for your help:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Sample Events&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chainData.PremiseMessageChainTracer&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;beginChain&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Message&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;chain&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;#5:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Begin&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C369823455-7843-44D7-89E3-SAB21BF361F24F&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;Request&lt;/SPAN&gt;]&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chainData.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C369823655-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C369823-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C3698sdss23-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;attached-email-body.txt&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;11&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessorr$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C3698saaa23-7843-44D7-89E3-B21BF361566F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[&lt;SPAN class=""&gt;Unknown&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;10&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.ComponentProcessor$PerMessageProcessor&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;processMessageComponents&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;FINER:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Processing&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;message&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class=""&gt;0C3698sdaa23-7843-44D7-89E3-B21BF361F24F&lt;/SPAN&gt;]&lt;SPAN class=""&gt;:&lt;/SPAN&gt;[[&lt;SPAN class=""&gt;EXT&lt;/SPAN&gt;] [&lt;SPAN class=""&gt;LibraryLink&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;Library&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Link&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;of&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;the&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Day&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;2023-05-09_attached-email-body&lt;/SPAN&gt;]&amp;nbsp;&lt;SPAN class=""&gt;took:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;May&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;9&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;2023&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;5:46:00&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;com.vontu.messaging.chain.imagepreclassifier.ImagePreclassifierManager&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;applyPrefiltersOnImages&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;INFO:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Skipping&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;component:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;unknown&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;image&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;filtering&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;as&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;required&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;component.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;PROPS.CONF&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;[auditrdata]&lt;/P&gt;
&lt;P class=""&gt;SHOULD_LINEMERGE=false&lt;/P&gt;
&lt;P class=""&gt;LINE_BREAKER=([\r\n]+)\w+\s\d{2},\s\d{4}&lt;/P&gt;
&lt;P class=""&gt;NO_BINARY_CHECK=true&lt;/P&gt;
&lt;P class=""&gt;CHARSET=UTF-8&lt;/P&gt;
&lt;P class=""&gt;disabled=false&lt;/P&gt;
&lt;P class=""&gt;TIME_PREFIX=^&lt;/P&gt;
&lt;P class=""&gt;TIME_FORMAT=%b %d, %Y %H:%M:%S&lt;/P&gt;
&lt;P class=""&gt;MAX_TIMESTAMP_LOOKAHEAD=30&lt;/P&gt;
&lt;P class=""&gt;TRUNCATE=5000&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 16:24:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642634#M222587</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-05-09T16:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642709#M222604</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;- I hope the sourcetype is correct as you said, so try the below configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[auditrdata]
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)\w+\s\d{1,2},\s\d{4}
NO_BINARY_CHECK=true
TIME_PREFIX=^
TIME_FORMAT=%b %d, %Y %I:%M:%S %p
MAX_TIMESTAMP_LOOKAHEAD=30
TRUNCATE=5000&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote if it does!!!&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 09:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642709#M222604</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-10T09:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642719#M222609</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you so much for your quick response, truly appreciate it. Now it's parsing one event as 2 events. I think the sample events I provided you should have 2 lines for each event, but the way I copied it looked like one line sorry about that. Each of the event should be as follow. Any recommendations would be highly appreciated. Thank you so much again.&lt;/P&gt;&lt;P&gt;May&amp;nbsp;9,&amp;nbsp;2023&amp;nbsp;5:46:00&amp;nbsp;AM&amp;nbsp;com.vontu.messaging.chainData.PremiseMessageChainTracer&amp;nbsp;beginChain&amp;nbsp;&lt;BR /&gt;FINER:&amp;nbsp;Message&amp;nbsp;chain&amp;nbsp;#5:&amp;nbsp;Begin&amp;nbsp;processing&amp;nbsp;message&amp;nbsp;[0C369823455-7843-44D7-89E3-SAB21BF361F24F]&amp;nbsp;from&amp;nbsp;[Request].&lt;/P&gt;&lt;P&gt;May&amp;nbsp;9,&amp;nbsp;2023&amp;nbsp;5:46:00&amp;nbsp;AM&amp;nbsp;com.vontu.messaging.chainData.ComponentProcessor PerMessageProcessor&amp;nbsp;processMessageComponents&amp;nbsp;&lt;BR /&gt;FINER:&amp;nbsp;Processing&amp;nbsp;of&amp;nbsp;message&amp;nbsp;[0C369823655-7843-44D7-89E3-B21BF361F24F]:[Unknown]&amp;nbsp;took:&amp;nbsp;0&amp;nbsp;ms&lt;/P&gt;&lt;P&gt;May&amp;nbsp;9,&amp;nbsp;2023&amp;nbsp;5:46:00&amp;nbsp;AM&amp;nbsp;com.vontu.messaging.chain.ComponentProcessorPerMessageProcessor&amp;nbsp;processMessageComponents&lt;BR /&gt;FINER:&amp;nbsp;Processing&amp;nbsp;of&amp;nbsp;message&amp;nbsp;[0C369823-7843-44D7-89E3-B21BF361F24F]:[Unknown]&amp;nbsp;took:&amp;nbsp;0&amp;nbsp;ms&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 18:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642719#M222609</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-05-09T18:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642735#M222616</link>
      <description>&lt;P&gt;Adding to&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;'s suggestion, try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[auditrdata]
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)\w+\s\d{1,2},\s\d{4}
NO_BINARY_CHECK=true
TIME_PREFIX=^
TIME_FORMAT=%b %d, %Y %I:%M:%S %p
MAX_TIMESTAMP_LOOKAHEAD=30
TRUNCATE=5000&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 20:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642735#M222616</guid>
      <dc:creator>m_pham</dc:creator>
      <dc:date>2023-05-09T20:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642736#M222617</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;the problem is in Line Breaker&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER=([\r\n]+)\w+\s\d{1,2},\s\d{4}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 20:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642736#M222617</guid>
      <dc:creator>goncalocoelho</dc:creator>
      <dc:date>2023-05-09T20:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642753#M222622</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162652"&gt;@goncalocoelho&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228716"&gt;@m_pham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much you all, truly appreciate it. Let me try with this and let you know how it goes. Thank you so much again.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 03:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642753#M222622</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-05-10T03:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642777#M222630</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;- Just updated my original response based on the change that you asked.&lt;/P&gt;&lt;P&gt;Just updated the LINE_BREAKER to&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;([\r\n]+)\w+\s\d{1,2},\s\d{4}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try original response now.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 09:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642777#M222630</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-10T09:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642939#M222687</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228716"&gt;@m_pham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162652"&gt;@goncalocoelho&lt;/a&gt;&amp;nbsp;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much again. Now events are parsing without doubling up (Multiple) events within single event. But now issue with the Line that has the TIMESTAMP. Every event is missing Line that has the TIMESTAMP and showing as follow. Any help will be highly appreciated, thank you again.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Showing Now:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;FINER:&amp;nbsp;Message&amp;nbsp;chain&amp;nbsp;#5:&amp;nbsp;Begin&amp;nbsp;processing&amp;nbsp;message&amp;nbsp;[0C369823455-7843-44D7-89E3-SAB21BF361F24F]&amp;nbsp;from&amp;nbsp;[Request].&lt;/P&gt;&lt;P&gt;FINER:&amp;nbsp;Processing&amp;nbsp;of&amp;nbsp;message&amp;nbsp;[0C369823655-7843-44D7-89E3-B21BF361F24F]:[Unknown]&amp;nbsp;took:&amp;nbsp;0&amp;nbsp;ms&lt;/P&gt;&lt;P&gt;FINER:&amp;nbsp;Processing&amp;nbsp;of&amp;nbsp;message&amp;nbsp;[0C369823-7843-44D7-89E3-B21BF361F24F]:[Unknown]&amp;nbsp;took:&amp;nbsp;0&amp;nbsp;ms&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Should be:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;May&amp;nbsp;9,&amp;nbsp;2023&amp;nbsp;5:46:00&amp;nbsp;AM&amp;nbsp;com.vontu.messaging.chainData.PremiseMessageChainTracer&amp;nbsp;beginChain&amp;nbsp;&lt;BR /&gt;FINER:&amp;nbsp;Message&amp;nbsp;chain&amp;nbsp;#5:&amp;nbsp;Begin&amp;nbsp;processing&amp;nbsp;message&amp;nbsp;[0C369823455-7843-44D7-89E3-SAB21BF361F24F]&amp;nbsp;from&amp;nbsp;[Request].&lt;/P&gt;&lt;P&gt;May&amp;nbsp;9,&amp;nbsp;2023&amp;nbsp;5:46:00&amp;nbsp;AM&amp;nbsp;com.vontu.messaging.chainData.ComponentProcessor PerMessageProcessor&amp;nbsp;processMessageComponents&amp;nbsp;&lt;BR /&gt;FINER:&amp;nbsp;Processing&amp;nbsp;of&amp;nbsp;message&amp;nbsp;[0C369823655-7843-44D7-89E3-B21BF361F24F]:[Unknown]&amp;nbsp;took:&amp;nbsp;0&amp;nbsp;ms&lt;/P&gt;&lt;P&gt;May&amp;nbsp;9,&amp;nbsp;2023&amp;nbsp;5:46:00&amp;nbsp;AM&amp;nbsp;com.vontu.messaging.chain.ComponentProcessorPerMessageProcessor&amp;nbsp;processMessageComponents&lt;BR /&gt;FINER:&amp;nbsp;Processing&amp;nbsp;of&amp;nbsp;message&amp;nbsp;[0C369823-7843-44D7-89E3-B21BF361F24F]:[Unknown]&amp;nbsp;took:&amp;nbsp;0&amp;nbsp;ms&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 03:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642939#M222687</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-05-11T03:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642957#M222698</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;- Try &lt;STRONG&gt;btool&lt;/STRONG&gt; and &lt;STRONG&gt;show config&lt;/STRONG&gt; CLI command to see what configuration is placed for this sourcetype and there is no conflicting configuration already present in your Splunk environment.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 05:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642957#M222698</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-11T05:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642999#M222717</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162652"&gt;@goncalocoelho&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228716"&gt;@m_pham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much again, this is completely new ingestion and no conflict found. Now is one interesting thing here, getting some of the events with the proper structure (with TIMESTAMP Line or no missing line) and some other events without that, thinking there might be issues (or inconsistency) with the format of the TIMESTAMP causing that issue. What you think? If this is the issue, what should I do, any recommendation would be highly &amp;nbsp;appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 09:43:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/642999#M222717</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-05-11T09:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix issue with parsing events (log files)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/643020#M222728</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;- The recommendation is to first find the different format that is causing the issue (or find all the different formats) and then based on that we maybe able to suggest something.&lt;/P&gt;&lt;P&gt;* Also it is unusual for a single system to generate two different timestamp formats for the same data.&lt;/P&gt;&lt;P&gt;* It could be either a different host, or different source.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 11:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-issue-with-parsing-events-log-files/m-p/643020#M222728</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-11T11:25:09Z</dc:date>
    </item>
  </channel>
</rss>

