All Apps and Add-ons

Splunk queries

anandhalagarasa
Path Finder

General queries

0 Karma

woodcock
Esteemed Legend

Try this

SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE = !%&#ThisIsGarbageRegexThatWillNeverMatch!%&#

cpetterborg
SplunkTrust
SplunkTrust
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi anandhalagarasan,
you have to insert in your sourcetype stanza of your props.conf the option SHOULD_LINEMERGE= true and maybe identify start point event.
I suggest to download an example of your configuration files and try to ingest it using the web interface, in this way you can immediately set your sourcetype.
Bye.
Giuseppe

0 Karma

anandhalagarasa
Path Finder

So kindly help on this request.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

You have edited your question to be completely useless in any context. Why did you do that?

It is also bad form to down vote a response that is not incorrect, even if it doesn't directly answer your question. If it is still correct, then you should not down vote an answer.

It is also GOOD form to accept an answer that does answer your question.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...