<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple LINE_BREAKER regex in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152806#M42820</link>
    <description>&lt;P&gt;Hm. I'd also suggest replacing those \r\n with an actual linebreak. Have a look &lt;A href="http://answers.splunk.com/answers/10532/new-line-appears-in-event-as-n-how-can-i-replace-them-with-a-new-line.html"&gt;here&lt;/A&gt; and see if it works for you.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2015 12:25:30 GMT</pubDate>
    <dc:creator>jeffland</dc:creator>
    <dc:date>2015-04-21T12:25:30Z</dc:date>
    <item>
      <title>Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152799#M42813</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I'll cut straight to the chase.  I have a sourcetype that contains 2 log sources.  Both are broken correctly using the props entry&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TIME_PREFIX = ^
TIME_FORMAT= %Y-%m-%dT%H:%M:%S%:z
SHOULD_LINEMERGE = false
BREAK_ONLY_BEFORE_DATE = true
LINE_BREAKER = ([\r\n]+)
TRUNCATE = 999999
TRANSFORMS-changeSourcetype1 = psm-set-sourcetype, asm-set-sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, one of the sources contains a lot of visible EOL terminators &lt;CODE&gt;source_NR=NR\r\n\r\n&lt;/CODE&gt;.  It is now required for the visible EOL terminators to be parsed as actual EOLs.&lt;/P&gt;

&lt;P&gt;I've tried to apply various types of multi regex on the LINE_BREAKER to no avail.  From what I've read, it is possible, but anything I try fails and breaks any line breaking.&lt;/P&gt;

&lt;P&gt;A few things I've tried:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;([\r\n]+)|([\\r\\n]+)
([\r\n]+)|\\r\\n
([\r\n]+)(\\r)(\\n)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The list goes on.&lt;/P&gt;

&lt;P&gt;Any advice would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Steve&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 09:12:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152799#M42813</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2015-04-21T09:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152800#M42814</link>
      <description>&lt;P&gt;I haven't fully understood what behavior you need. New events are supposed to begin just like they did until now, but inside of them you need linebreaks (i.e. there need to be new lines at the beginning of an event)?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 09:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152800#M42814</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-04-21T09:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152801#M42815</link>
      <description>&lt;P&gt;2015-04-21T10:51:26+01:00 &amp;lt;&amp;gt; ASM: unit_hostname="&amp;lt;&amp;gt;",management_ip_address="&amp;lt;&amp;gt;",http_class_name="/Common/pl_restricted_L0_prod",web_application_name="/Common/pl_restricted_L0_prod",policy_name="/Common/pl_restricted_L0_prod",policy_apply_date="2015-04-20 21:44:42",violations="Attack signature detected",support_id="16995741371937106148",request_status="blocked",response_code="0",ip_client="46.201.133.82",route_domain="0",method="GET",protocol="HTTP",query_string="",x_forwarded_for_header_value="N/A",sig_ids="300000002",sig_names="parimatchru",date_time="2015-04-21 10:51:25",severity="Error",attack_type="Abuse of Functionality",geo_location="UA",ip_address_intelligence="N/A",username="N/A",session_id="8f08ae0f2fbd5d82",src_port="55263",dest_port="80",dest_ip="&amp;lt;&amp;gt;",sub_violations="",virus_name="N/A",uri="/bet/ru",request="GET /bet/ru HTTP/1.1\r\nHost: sports.whgaming.com\r\nConnection: keep-alive\r\nAccept: image/webp,&lt;EM&gt;/&lt;/EM&gt;;q=0.8\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1717.129 Amigo/32.0.1717.129 MRCHROME SOC Safari/537.36\r\nReferer: &lt;A href="http://start.parimatchru.com/bonusnew/?btag=a_3615b_234c_231947&amp;amp;id=231947%5Cr%5CnAccept-Encoding:" target="_blank"&gt;http://start.parimatchru.com/bonusnew/?btag=a_3615b_234c_231947&amp;amp;id=231947\r\nAccept-Encoding:&lt;/A&gt; gzip,deflate,sdch\r\nAccept-Language: ru-RU,ru;q=0.8,en-US;q=0.6,en;q=0.4\r\nCookie: banner_click=aleshasavin,NA,NA,NA,admap:159955966FE625989E443CA9CEA4BE36CCBBFCB%3Bsource:[var1]%3Bzone:1487412695%3Bchannel:185050786; clickinfo=pid=185050786&amp;amp;bid=1487412695; vars_info=; source_NR=NR\r\n\r\n"#015&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152801#M42815</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2020-09-28T19:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152802#M42816</link>
      <description>&lt;P&gt;Hi Jeffland,&lt;BR /&gt;
The above is an event that we want to break down.  So for each &lt;CODE&gt;\r\n&lt;/CODE&gt; we require the following line on a new line.  The alternative I could try is to setup a SEDCMD in transforms and replace each &lt;CODE&gt;\r\n&lt;/CODE&gt; with a &lt;CODE&gt;,&lt;/CODE&gt;.  This I believe would also fix the auto field extraction.&lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Steve&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 10:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152802#M42816</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2015-04-21T10:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152803#M42817</link>
      <description>&lt;P&gt;I have the feeling that your event text was somehow corrupted when you posted it. Could you post it as a text file, or as code? There are some "rn" in there, also one with backslashes, but I doubt this is what you wanted to post.&lt;BR /&gt;
As for your linebreaker, the places you define there will lead to an "event break", i.e. every time the regex fits your data there will be a new event. That's why I doubt you can achieve what you need with the line breaker. But I still haven't fully understood what you need your event to look like. Do you want splunk to display a line break when it shows the events as returned from a search?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 11:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152803#M42817</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-04-21T11:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152804#M42818</link>
      <description>&lt;P&gt;I'll have to post it as an "answer" as the comment box won't allow the volume of text.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 12:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152804#M42818</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2015-04-21T12:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152805#M42819</link>
      <description>&lt;P&gt;This is the raw event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-04-21T12:55:25+01:00 &amp;lt;hostname&amp;gt; ASM: unit_hostname="&amp;lt;hostname&amp;gt;",management_ip_address="&amp;lt;IP&amp;gt;",http_class_name="/Common/pl_sports_com_L1_prod",web_application_name="/Common/pl_sports_com_L1_prod",policy_name="/Common/pl_sports_com_L1_prod",policy_apply_date="2015-04-20 22:59:53",violations="Web scraping detected",support_id="16995741371944062892",request_status="blocked",response_code="0",ip_client="185.17.184.228",route_domain="0",method="GET",protocol="HTTPS",query_string="action=event&amp;amp;ev_id=7447953&amp;amp;version=1",x_forwarded_for_header_value="N/A",sig_ids="",sig_names="",date_time="2015-04-21 12:55:25",severity="Error",attack_type="Web Scraping",geo_location="NL",ip_address_intelligence="N/A",username="N/A",session_id="a27f9feb0b622a04",src_port="40567",dest_port="443",dest_ip="&amp;lt;IP&amp;gt;",sub_violations="",virus_name="N/A",uri="/bir_xml",request="GET /bir_xml?action=event&amp;amp;ev_id=7447953&amp;amp;version=1 HTTP/1.1\r\nHost: &amp;lt;URL&amp;gt;\r\nCookie: TS0158e29b=0148840b44c2771c7edfa9b3305f349c56fc28fecb0c11fc5c4b963f7e860ace7b26c42578; TS0197b840=0148840b4416795c008c4e4b7adc1e097f180a2c1e661ae566acbeafbd41be90e94db247b64d197bb6324d0ffd8ba54611a9e1ce03; sitePreference=DESKTOP\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\nAccept-Language: en-us,en;q=0.5\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:16.0) Gecko/20100101 Firefox/16.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n"#015
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is how I thought the LINE_BREAKER would have changed it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-04-21T12:55:25+01:00 &amp;lt;hostname&amp;gt; ASM: unit_hostname="&amp;lt;hostname&amp;gt;",management_ip_address="&amp;lt;IP&amp;gt;",http_class_name="/Common/pl_sports_com_L1_prod",web_application_name="/Common/pl_sports_com_L1_prod",policy_name="/Common/pl_sports_com_L1_prod",policy_apply_date="2015-04-20 22:59:53",violations="Web scraping detected",support_id="16995741371944062892",request_status="blocked",response_code="0",ip_client="185.17.184.228",route_domain="0",method="GET",protocol="HTTPS",query_string="action=event&amp;amp;ev_id=7447953&amp;amp;version=1",x_forwarded_for_header_value="N/A",sig_ids="",sig_names="",date_time="2015-04-21 12:55:25",severity="Error",attack_type="Web Scraping",geo_location="NL",ip_address_intelligence="N/A",username="N/A",session_id="a27f9feb0b622a04",src_port="40567",dest_port="443",dest_ip="&amp;lt;IP&amp;gt;",sub_violations="",virus_name="N/A",uri="/bir_xml",request="GET /bir_xml?action=event&amp;amp;ev_id=7447953&amp;amp;version=1 HTTP/1.1\r\n
Host: &amp;lt;URL&amp;gt;\r\n
Cookie: TS0158e29b=0148840b44c2771c7edfa9b3305f349c56fc28fecb0c11fc5c4b963f7e860ace7b26c42578; TS0197b840=0148840b4416795c008c4e4b7adc1e097f180a2c1e661ae566acbeafbd41be90e94db247b64d197bb6324d0ffd8ba54611a9e1ce03; sitePreference=DESKTOP\r\n
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\n
Accept-Language: en-us,en;q=0.5\r\n
Connection: keep-alive\r\n
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:16.0) Gecko/20100101 Firefox/16.0\r\n
Accept-Encoding: gzip, deflate\r\n\r\n"#015
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I'm starting to lean towards using transforms to replace the &lt;CODE&gt;\r\n&lt;/CODE&gt; so that the whole event is standardised?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 12:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152805#M42819</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2015-04-21T12:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152806#M42820</link>
      <description>&lt;P&gt;Hm. I'd also suggest replacing those \r\n with an actual linebreak. Have a look &lt;A href="http://answers.splunk.com/answers/10532/new-line-appears-in-event-as-n-how-can-i-replace-them-with-a-new-line.html"&gt;here&lt;/A&gt; and see if it works for you.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 12:25:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152806#M42820</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-04-21T12:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152807#M42821</link>
      <description>&lt;P&gt;nice &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  Thanks jeffland.  very much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 13:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152807#M42821</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2015-04-21T13:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LINE_BREAKER regex</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152808#M42822</link>
      <description>&lt;P&gt;Just for completeness &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;My props stanza is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[f5]
TIME_PREFIX = ^
TIME_FORMAT= %Y-%m-%dT%H:%M:%S%:z
BREAK_ONLY_BEFORE_DATE = True
LINE_BREAKER = ([\r\n\$])
TRUNCATE = 999999
TRANSFORMS-changeSourcetype1 = psm-set-sourcetype, asm-set-sourcetype
SEDCMD-newline = s/\\r\\n/,/g
SEDCMD-eventend = s/#015//g
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So now all the fields are correctly extracted and the annoying #015 is removed.  Plus the other source is untouched.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2015 06:17:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multiple-LINE-BREAKER-regex/m-p/152808#M42822</guid>
      <dc:creator>cdstealer</dc:creator>
      <dc:date>2015-04-22T06:17:00Z</dc:date>
    </item>
  </channel>
</rss>

