<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to use structured field extraction (PSV in this case) that works with multiline field values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229428#M67935</link>
    <description>&lt;P&gt;If it works for you, you should convert this comment to an answer and mark it as accepted, so others can see your problem is fixed &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2016 08:25:56 GMT</pubDate>
    <dc:creator>DMohn</dc:creator>
    <dc:date>2016-01-14T08:25:56Z</dc:date>
    <item>
      <title>Is there a way to use structured field extraction (PSV in this case) that works with multiline field values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229426#M67933</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;

&lt;P&gt;I have been trying with no luck today to do a structured field extraction using the "Add Data" function of my test environment:&lt;BR /&gt;
Splunk Version 6.3.1&lt;BR /&gt;
RHEL&lt;/P&gt;

&lt;P&gt;The data looks something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2016-01-11 08:22:11.048 +10:00|SDLC||someuniquedata|Appname|ver|11|Information| Single line message
2016-01-11 08:22:12.249 +10:00|SDLC||someuniquedata|Appname|ver|11|Warning| multi-line message part 1
 multi-line message part 2
 multi-line message part 3
2016-01-11 08:22:26.227 +10:00|SDLC||someuniquedata|Appname|ver|48|Information| Single line message
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But when I configure the parameters to do a PSV field extraction, the multiline message part 2 and 3 lines are created as separate events. At this point, since I have used many combinations of &lt;CODE&gt;SHOULD_LINEMERGE&lt;/CODE&gt; ( and dependent config options such as &lt;CODE&gt;BREAK_ONLY_*&lt;/CODE&gt;) and &lt;CODE&gt;LINE_BREAK&lt;/CODE&gt;  to no avail, I am left with the sinking feeling that this is just the way this type of structured data is handled...&lt;/P&gt;

&lt;P&gt;Is there something else (perhaps outside of the gui) that I could try?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Luke &lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2016 08:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229426#M67933</guid>
      <dc:creator>ljolly</dc:creator>
      <dc:date>2016-01-12T08:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to use structured field extraction (PSV in this case) that works with multiline field values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229427#M67934</link>
      <description>&lt;P&gt;I managed to answer my own question, which is nice. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[psv-iis]
SHOULD_LINEMERGE = true
NO_BINARY_CHECK = true
category = Custom
disabled = false
REPORT-extractpsv = extractpsv-iis
pulldown_type = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[extractpsv-iis]
DELIMS = "|"
FIELDS = Timestamp , Environment , ClientIP , CorrelationId , ApplicationName , ApplicationVersion , ThreadId , Level , Message
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Luke&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 04:38:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229427#M67934</guid>
      <dc:creator>ljolly</dc:creator>
      <dc:date>2016-01-13T04:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to use structured field extraction (PSV in this case) that works with multiline field values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229428#M67935</link>
      <description>&lt;P&gt;If it works for you, you should convert this comment to an answer and mark it as accepted, so others can see your problem is fixed &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 08:25:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229428#M67935</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2016-01-14T08:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to use structured field extraction (PSV in this case) that works with multiline field values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229429#M67936</link>
      <description>&lt;P&gt;I managed to answer my own question, which is nice. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[psv-iis]
SHOULD_LINEMERGE = true
NO_BINARY_CHECK = true
category = Custom
disabled = false
REPORT-extractpsv = extractpsv-iis
pulldown_type = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[extractpsv-iis]
DELIMS = "|"
FIELDS = Timestamp , Environment , ClientIP , CorrelationId , ApplicationName , ApplicationVersion , ThreadId , Level , Message
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Luke&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 09:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-use-structured-field-extraction-PSV-in-this/m-p/229429#M67936</guid>
      <dc:creator>ljolly</dc:creator>
      <dc:date>2016-01-14T09:15:19Z</dc:date>
    </item>
  </channel>
</rss>

