<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RegEx Pattern for Event Break in SourceType in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252020#M75354</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I am trying to determine the RegEx pattern for the Event Break. Below is an example event. A new event starts on the line preceding the  "Information Message: Processing file:" text. The process number and the timestamp varies on the first line as does the info that follows  "Information Message: Processing file:" until the next event starts.&lt;/P&gt;

&lt;P&gt;1050746893 2016-11-25 05:36:02,518 [7] DEBUG DealerTrackImageDecoder, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null - &lt;BR /&gt;
Information Message: Processing file: C:\dealertrack\contracts\0C075017-0-1899123053557contract.xml&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Thanks in advance for any help,&lt;/P&gt;

&lt;P&gt;Neil&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2016 20:43:22 GMT</pubDate>
    <dc:creator>neiowe</dc:creator>
    <dc:date>2016-11-30T20:43:22Z</dc:date>
    <item>
      <title>RegEx Pattern for Event Break in SourceType</title>
      <link>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252020#M75354</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I am trying to determine the RegEx pattern for the Event Break. Below is an example event. A new event starts on the line preceding the  "Information Message: Processing file:" text. The process number and the timestamp varies on the first line as does the info that follows  "Information Message: Processing file:" until the next event starts.&lt;/P&gt;

&lt;P&gt;1050746893 2016-11-25 05:36:02,518 [7] DEBUG DealerTrackImageDecoder, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null - &lt;BR /&gt;
Information Message: Processing file: C:\dealertrack\contracts\0C075017-0-1899123053557contract.xml&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Thanks in advance for any help,&lt;/P&gt;

&lt;P&gt;Neil&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 20:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252020#M75354</guid>
      <dc:creator>neiowe</dc:creator>
      <dc:date>2016-11-30T20:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: RegEx Pattern for Event Break in SourceType</title>
      <link>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252021#M75355</link>
      <description>&lt;P&gt;Can you check if this regex works for event breaker:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^\d{10}\s
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Dec 2016 04:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252021#M75355</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-12-01T04:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: RegEx Pattern for Event Break in SourceType</title>
      <link>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252022#M75356</link>
      <description>&lt;P&gt;Thanks. I wish it was that easy. That 10 digit number is the process number  and is included on each process entry. However, there are most time multiple processes that make up what I am wanting to be a single event.  The text "Information Message: Processing file:" on the second line is what indicates that a new file is being processed. I want to include all processes below that until the next "Information Message: Processing file:"  into a single event.&lt;/P&gt;

&lt;P&gt;I can use "Information Message: Processing file:"  as the pattern and that gets me close, but I need the line right before "Information Message: Processing file:"  to be included in the event also. &lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 14:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/RegEx-Pattern-for-Event-Break-in-SourceType/m-p/252022#M75356</guid>
      <dc:creator>neiowe</dc:creator>
      <dc:date>2016-12-01T14:02:14Z</dc:date>
    </item>
  </channel>
</rss>

