<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: strftime format for event breaks not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198684#M57487</link>
    <description>&lt;P&gt;OK, just to verfy - you know that &lt;CODE&gt;BREAK_ONLY/MUST_NOT_BREAK&lt;/CODE&gt; etc only are valid with &lt;CODE&gt;SHOULD_LINEMERGE = true&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;And conversely - &lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt; is only honoured with &lt;CODE&gt;SHOULD_LINEMERGE = false&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;And you are sure that the sourcetype is correct, i.e. so that the settings are applied at all. And that they are in the correct place (indexer/heavy forwarder)&lt;/P&gt;</description>
    <pubDate>Thu, 27 Mar 2014 06:46:52 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2014-03-27T06:46:52Z</dc:date>
    <item>
      <title>strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198677#M57480</link>
      <description>&lt;P&gt;Event breaks based on strftime format for weblogic log events that are not being parsed correctly. e.g. It seems to be interpreting '1432711901' as a timestamp in the following logs.&lt;BR /&gt;
Weird thing is this is happening intermittently, parsing some correctly but not all.&lt;/P&gt;

&lt;P&gt;my props.conf entry on the indexer is&lt;BR /&gt;
[app_wls]&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 30&lt;BR /&gt;
NO_BINARY_CHECK=1&lt;BR /&gt;
TIME_FORMAT=%b %d, %Y %I:%M:%S %p&lt;BR /&gt;
TIME_PREFIX = ^&lt;/P&gt;

&lt;P&gt;Raw logs for a single event is as follows :&lt;/P&gt;

&lt;P&gt;Mar 25, 2014 4:22:01 PM au.com.mydomain.common.logging.LoggerTrace warn&lt;BR /&gt;
WARNING: Unable to configure audit log meta data. Param not of type Request. Is a: au.com.mydomain.common.configdata&lt;BR /&gt;
.GetConfigDataRequest&lt;BR /&gt;
1432711901 [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewor&lt;BR /&gt;
k.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.f&lt;BR /&gt;
actory.support.DisposableBeanAdapter@1d9774a] for attribute 'basicDateTimeConverter' because FacesRequestAttributes&lt;BR /&gt;
does not support such callbacks&lt;BR /&gt;
1432711904 [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewor&lt;BR /&gt;
k.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.f&lt;BR /&gt;
actory.support.DisposableBeanAdapter@ff86e9] for attribute 'basicDateConverter' because FacesRequestAttributes does&lt;BR /&gt;
not support such callbacks&lt;BR /&gt;
1432712079 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@15d7a3d] for attribute 'transRefValidator' because FacesRequestAttributes does&lt;BR /&gt;
 not support such callbacks&lt;BR /&gt;
1432712079 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@45316] for attribute 'transRefConverter' because FacesRequestAttributes does n&lt;BR /&gt;
ot support such callbacks&lt;BR /&gt;
1432712080 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@f6f2c2] for attribute 'decimalPlacesValidator' because FacesRequestAttributes&lt;BR /&gt;
does not support such callbacks&lt;BR /&gt;
1432712081 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@bbac62] for attribute 'minMaxDecimalValidator' because FacesRequestAttributes&lt;BR /&gt;
does not support such callbacks&lt;BR /&gt;
1432712086 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@c085f6] for attribute 'paymentInvestigationTypeConverter' because FacesRequest&lt;BR /&gt;
Attributes does not support such callbacks&lt;BR /&gt;
1432712086 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@16bcb2d] for attribute 'paymentInvestigationStatusConverter' because FacesRequ&lt;BR /&gt;
estAttributes does not support such callbacks&lt;BR /&gt;
1432712087 [[ACTIVE] ExecuteThread: '11' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewo&lt;BR /&gt;
rk.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.&lt;BR /&gt;
factory.support.DisposableBeanAdapter@3d3019] for attribute 'simpleDateConverter' because FacesRequestAttributes doe&lt;BR /&gt;
s not support such callbacksI&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198677#M57480</guid>
      <dc:creator>noveix</dc:creator>
      <dc:date>2020-09-28T16:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198678#M57481</link>
      <description>&lt;P&gt;Could it be that your event breaks work fine at 10,11 or 12 o'clock?&lt;/P&gt;

&lt;P&gt;Then the problem might be in your &lt;CODE&gt;TIME_FORMAT&lt;/CODE&gt;, and most of the times these things happen (improper event breaking) is when splunk fails to parse timestamps.&lt;/P&gt;

&lt;P&gt;You define your &lt;CODE&gt;TIME_FORMAT&lt;/CODE&gt; with %I for the hour portion (uppercase "i"), which means that values from 01 .. 12 are valid.&lt;/P&gt;

&lt;P&gt;I believe that changing to %l (lowercase "L") instead might do the trick, since this means hours from 1 .. 12, i.e. without the leading zero. &lt;/P&gt;

&lt;P&gt;see &lt;A href="http://www.strftime.net"&gt;www.strftime.net&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;

&lt;P&gt;PS. The reason that numbers like 1432712121 get parsed as timestamps, is that splunk, when failing to detect a proper timestamp according to your configuration may revert to default auto-detecting behaviour, and a numeric string of this size and value can be interpreted as an epoch timestamp (around May 27 2015).&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 07:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198678#M57481</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-25T07:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198679#M57482</link>
      <description>&lt;P&gt;Hi Kristian&lt;/P&gt;

&lt;P&gt;I tried &lt;BR /&gt;
TIME_FORMAT=%b %d, %Y %l:%M:%S %p    (lowercase 'L') and also&lt;/P&gt;

&lt;P&gt;TIME_FORMAT=%b %d, %Y %r&lt;BR /&gt;
still no luck ...&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 21:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198679#M57482</guid>
      <dc:creator>noveix</dc:creator>
      <dc:date>2014-03-25T21:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198680#M57483</link>
      <description>&lt;P&gt;more info .. seems to be when there is a line break within the logs then the log entries are not grouped into a single event&lt;/P&gt;

&lt;P&gt;so the following breaks, however if there was not line breaks then its recognised as a single event&lt;/P&gt;

&lt;P&gt;Mar 25, 2014 4:22:01 PM au.com.mydomain.common.logging.LoggerTrace warn&lt;BR /&gt;
WARNING: Unable to configure audit log meta data. Param not of type Request. Is a: au.com.mydomain.common.configdata&lt;BR /&gt;
.GetConfigDataRequest&lt;/P&gt;

&lt;P&gt;1432711901 [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'] WARN  org.springframewor&lt;BR /&gt;
k.web.context.request.FacesRequestAttributes  - Could not register destruction callback [org.springframework.beans.f&lt;BR /&gt;
actory.support.DisposableBeanAdapter@1d9774a] for attribute 'basicDateTimeConverter' because FacesRequestAttributes&lt;BR /&gt;
does not support such callbacks&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 22:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198680#M57483</guid>
      <dc:creator>noveix</dc:creator>
      <dc:date>2014-03-25T22:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198681#M57484</link>
      <description>&lt;P&gt;Still think it is timestamp-related. It almost always is. However, you may need to increase the value for &lt;CODE&gt;MAX_EVENTS&lt;/CODE&gt; (in props) to accommodate events with more than 256 lines. Also, you could try to force the linebreaking behaviour with &lt;CODE&gt;MUST_NOT_BREAK.../BREAK_ONLY...&lt;/CODE&gt; (also in props).&lt;/P&gt;

&lt;P&gt;Another option is to set &lt;CODE&gt;SHOULD_LINEMERGE = false&lt;/CODE&gt;, and use something like the following &lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt; regex;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE_BREAKER = ([\r\n]+)(?=[A-Z][a-z]{2}\s+\d+,\s+20\d\d\s+\d+:\d\d:\d\d\s+[AP]M)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which means that it should only break before a line that contains timestamps formatted as yours.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 18:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198681#M57484</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-26T18:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198682#M57485</link>
      <description>&lt;P&gt;Fixed a typo and some ambiguity regarding single/double digit dates.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 18:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198682#M57485</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-26T18:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198683#M57486</link>
      <description>&lt;P&gt;Hi Kristian&lt;BR /&gt;
Tried the LINE_BREAKER ... it took out the match group, in my case, the Timestamp, anyway I tried the BREAK_ONLY_BEFORE as well, still no good. I have verified my REGEX and its definitely correct, however its not parsing as expected.&lt;/P&gt;

&lt;P&gt;Thanks for your help with this, I think I will look at the Weblogic log setting to see if I can eliminate the extra newlines within the logs, this is the main cause of my issues.&lt;BR /&gt;
Appreciate your help !!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:14:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198683#M57486</guid>
      <dc:creator>noveix</dc:creator>
      <dc:date>2020-09-28T16:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: strftime format for event breaks not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198684#M57487</link>
      <description>&lt;P&gt;OK, just to verfy - you know that &lt;CODE&gt;BREAK_ONLY/MUST_NOT_BREAK&lt;/CODE&gt; etc only are valid with &lt;CODE&gt;SHOULD_LINEMERGE = true&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;And conversely - &lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt; is only honoured with &lt;CODE&gt;SHOULD_LINEMERGE = false&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;And you are sure that the sourcetype is correct, i.e. so that the settings are applied at all. And that they are in the correct place (indexer/heavy forwarder)&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 06:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/strftime-format-for-event-breaks-not-working/m-p/198684#M57487</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-27T06:46:52Z</dc:date>
    </item>
  </channel>
</rss>

