All Apps and Add-ons

SPlunk Bro App and how to separate data into multiple entries?

jngo
Observer

Greetings!

I have Splunk forwarder installed on a Bro IDS host and set all bro log files to be forwarded to a Splunk indexer. Currently I have one small issue. Sometime, when multiple smtp events are recorded at the same time in the bro smtp.log, these events are merged into one single entry when I perform search in Splunk. This also caused the field extraction to not work properly. Anyone knows how to separate the data into multiple entries?

Thanks.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

hi, this is most likely a linebreak problem -- if you can post anonymized samples of it not working, we can probably get it fixed.

0 Karma

djw1191
Explorer

I've had this same problem (http://answers.splunk.com/answers/154056/why-are-bro-smtp-logs-not-breaking-into-multiple-events.htm...). I was never able to solve the problem. When looking at the raw text logs, there was nothing obviously different between events that properly split and those that did not.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...