<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to line break raw events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705682#M238887</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a log file on the server which I ingested in splunk through input app where I defined the index , sourcetype and monitor statement in inputs.conf. Log file on the server looks like below:&lt;/P&gt;&lt;P&gt;xyz&lt;BR /&gt;asdfoasdf&lt;BR /&gt;asfanfafd&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;BR /&gt;sdfsdfja&lt;BR /&gt;agf[oija[gfojerg&lt;BR /&gt;fgoaierr&lt;BR /&gt;apodsifa[soigaiga[oiga[dogj&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;BR /&gt;sadfnasd;fiasfdoiasndf'i&lt;BR /&gt;dfdf&lt;BR /&gt;fd&lt;BR /&gt;garehaehseht&lt;BR /&gt;shse&lt;BR /&gt;thse&lt;BR /&gt;tjst&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;BR /&gt;asdf;nafdsknasdf&lt;BR /&gt;asdfknasdfln&lt;BR /&gt;asdf;nasdkfnasf&lt;BR /&gt;asogja'fja&lt;BR /&gt;foj'apogj&lt;BR /&gt;aogj&lt;BR /&gt;agf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try searching the log file in splunk, Logs are visible howerver events are not breaking as I expect it to come. I want events to be separated as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event 1:&lt;/P&gt;&lt;P&gt;xyz&lt;BR /&gt;asdfoasdf&lt;BR /&gt;asfanfafd&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;Event 2:&lt;/P&gt;&lt;P&gt;sdfsdfja&lt;BR /&gt;agf[oija[gfojerg&lt;BR /&gt;fgoaierr&lt;BR /&gt;apodsifa[soigaiga[oiga[dogj&lt;/P&gt;&lt;P&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event 3:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sadfnasd;fiasfdoiasndf'i&lt;BR /&gt;dfdf&lt;BR /&gt;fd&lt;BR /&gt;garehaehseht&lt;BR /&gt;shse&lt;BR /&gt;thse&lt;BR /&gt;tjst&lt;/P&gt;&lt;P&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;Event 4:&lt;/P&gt;&lt;P&gt;asdf;nafdsknasdf&lt;BR /&gt;asdfknasdfln&lt;BR /&gt;asdf;nasdkfnasf&lt;BR /&gt;asogja'fja&lt;BR /&gt;foj'apogj&lt;BR /&gt;aogj&lt;BR /&gt;agf&lt;/P&gt;&lt;P&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2024 13:04:46 GMT</pubDate>
    <dc:creator>Sailesh6891</dc:creator>
    <dc:date>2024-12-02T13:04:46Z</dc:date>
    <item>
      <title>How to line break raw events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705682#M238887</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a log file on the server which I ingested in splunk through input app where I defined the index , sourcetype and monitor statement in inputs.conf. Log file on the server looks like below:&lt;/P&gt;&lt;P&gt;xyz&lt;BR /&gt;asdfoasdf&lt;BR /&gt;asfanfafd&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;BR /&gt;sdfsdfja&lt;BR /&gt;agf[oija[gfojerg&lt;BR /&gt;fgoaierr&lt;BR /&gt;apodsifa[soigaiga[oiga[dogj&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;BR /&gt;sadfnasd;fiasfdoiasndf'i&lt;BR /&gt;dfdf&lt;BR /&gt;fd&lt;BR /&gt;garehaehseht&lt;BR /&gt;shse&lt;BR /&gt;thse&lt;BR /&gt;tjst&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;BR /&gt;asdf;nafdsknasdf&lt;BR /&gt;asdfknasdfln&lt;BR /&gt;asdf;nasdkfnasf&lt;BR /&gt;asogja'fja&lt;BR /&gt;foj'apogj&lt;BR /&gt;aogj&lt;BR /&gt;agf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try searching the log file in splunk, Logs are visible howerver events are not breaking as I expect it to come. I want events to be separated as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event 1:&lt;/P&gt;&lt;P&gt;xyz&lt;BR /&gt;asdfoasdf&lt;BR /&gt;asfanfafd&lt;BR /&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;Event 2:&lt;/P&gt;&lt;P&gt;sdfsdfja&lt;BR /&gt;agf[oija[gfojerg&lt;BR /&gt;fgoaierr&lt;BR /&gt;apodsifa[soigaiga[oiga[dogj&lt;/P&gt;&lt;P&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event 3:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sadfnasd;fiasfdoiasndf'i&lt;BR /&gt;dfdf&lt;BR /&gt;fd&lt;BR /&gt;garehaehseht&lt;BR /&gt;shse&lt;BR /&gt;thse&lt;BR /&gt;tjst&lt;/P&gt;&lt;P&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;Event 4:&lt;/P&gt;&lt;P&gt;asdf;nafdsknasdf&lt;BR /&gt;asdfknasdfln&lt;BR /&gt;asdf;nasdkfnasf&lt;BR /&gt;asogja'fja&lt;BR /&gt;foj'apogj&lt;BR /&gt;aogj&lt;BR /&gt;agf&lt;/P&gt;&lt;P&gt;:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705682#M238887</guid>
      <dc:creator>Sailesh6891</dc:creator>
      <dc:date>2024-12-02T13:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to line break raw events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705683#M238888</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274436"&gt;@Sailesh6891&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you tried to use LINE_BREKING option in props.conf?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your-sourcetype]
LINE_BREAKING = :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705683#M238888</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-02T13:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to line break raw events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705684#M238889</link>
      <description>&lt;P&gt;No, I have not used LINE_BREAKING option.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to create a props.conf under splunk_home$/etc/apps/local/&amp;nbsp;&lt;/P&gt;&lt;P&gt;and mention these 2 lines ?i.e [sourcetype] and LINE_BREAKING = &amp;nbsp;:::::::::::::::::::&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705684#M238889</guid>
      <dc:creator>Sailesh6891</dc:creator>
      <dc:date>2024-12-02T13:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to line break raw events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705685#M238890</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274436"&gt;@Sailesh6891&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's a best practive to create a custom add-on containing all the parsing rules for your data, also because I suppose that there are other parsing rules that you need to add.&lt;/P&gt;&lt;P&gt;but anyway you can also put this two lines in another props.conf.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 14:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-break-raw-events/m-p/705685#M238890</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-02T14:01:07Z</dc:date>
    </item>
  </channel>
</rss>

