<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk GUI seperating event in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666959#M228789</link>
    <description>&lt;P&gt;From splunk user we are receiving logs but when it comes to Splunk search head its splitting into different events&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expected log :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Oct 26 09:37:51 +02:00 10.191.248.38 -: Operation%%31051 # Minor # qaz# XYZ # 10.135.114.70 # Succeeded # Function:[Configuration Management][MML Command&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;PQR&amp;nbsp;ME:; # 2023-10-26 09:37:51#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;splunk dividing into two separate&amp;nbsp;events&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Oct 26 09:37:51 +02:00 10.191.248.38 -: Operation%%31051 # Minor # qaz# XYZ # 10.135.114.70&amp;nbsp; # Succeeded # Function:[Configuration Management][MML Command&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;amp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;LST ME:; # 2023-10-26 09:37:51#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How can i resolve this cannot combine this two because getting seperate event not one after another&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Nov 2023 07:04:10 GMT</pubDate>
    <dc:creator>Komal0113</dc:creator>
    <dc:date>2023-11-01T07:04:10Z</dc:date>
    <item>
      <title>Splunk GUI seperating event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666959#M228789</link>
      <description>&lt;P&gt;From splunk user we are receiving logs but when it comes to Splunk search head its splitting into different events&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expected log :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Oct 26 09:37:51 +02:00 10.191.248.38 -: Operation%%31051 # Minor # qaz# XYZ # 10.135.114.70 # Succeeded # Function:[Configuration Management][MML Command&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;PQR&amp;nbsp;ME:; # 2023-10-26 09:37:51#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;splunk dividing into two separate&amp;nbsp;events&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Oct 26 09:37:51 +02:00 10.191.248.38 -: Operation%%31051 # Minor # qaz# XYZ # 10.135.114.70&amp;nbsp; # Succeeded # Function:[Configuration Management][MML Command&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;amp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;LST ME:; # 2023-10-26 09:37:51#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How can i resolve this cannot combine this two because getting seperate event not one after another&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 07:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666959#M228789</guid>
      <dc:creator>Komal0113</dc:creator>
      <dc:date>2023-11-01T07:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk GUI seperating event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666960#M228790</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261277"&gt;@Komal0113&lt;/a&gt;&amp;nbsp;Some more details needed:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can we have your Splunk Search Query pls (remove any hostname, ip address, etc from the search query)&lt;/LI&gt;&lt;LI&gt;Are you using HF or not&lt;/LI&gt;&lt;LI&gt;mostly the props/transforms causes this issue. can we have your props/transforms(only the portion responsible for this APP/add-on/TA is enough)&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 01 Nov 2023 07:26:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666960#M228790</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-11-01T07:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk GUI seperating event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666962#M228791</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;1) In splunk search query we are using index name for search&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Receiving logs via udp port&lt;/P&gt;
&lt;P&gt;3) props conf&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;LINE_BREAKER = (\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2})
SHOULD_LINEMERGE = false&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 11:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666962#M228791</guid>
      <dc:creator>Komal0113</dc:creator>
      <dc:date>2023-11-01T11:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk GUI seperating event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666966#M228795</link>
      <description>&lt;P&gt;1. Search head is the component which spawns searches against indexers which hold the already indexed data. So I assume you meant that you're sending data in some format but it's getting improperly split into events.&lt;/P&gt;&lt;P&gt;2. Sending raw tcp or udp data stream directly to a Splunk component is not the preferred way to go (for several reasons which I will not dig into at this point).&lt;/P&gt;&lt;P&gt;3. What do these events look like on the wire? I'm not 100% sure but I think they might get split at datagram boundary regardless of other settings.&lt;/P&gt;&lt;P&gt;4. Your "split" set of events contains a second event which is _not_a part of the original event. A typo in preparation of the mockup data?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 08:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-GUI-seperating-event/m-p/666966#M228795</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-01T08:07:46Z</dc:date>
    </item>
  </channel>
</rss>

