All Apps and Add-ons

Splunk queries

anandhalagarasa
Path Finder

General queries

0 Karma

woodcock
Esteemed Legend

Try this

SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE = !%&#ThisIsGarbageRegexThatWillNeverMatch!%&#

cpetterborg
SplunkTrust
SplunkTrust
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi anandhalagarasan,
you have to insert in your sourcetype stanza of your props.conf the option SHOULD_LINEMERGE= true and maybe identify start point event.
I suggest to download an example of your configuration files and try to ingest it using the web interface, in this way you can immediately set your sourcetype.
Bye.
Giuseppe

0 Karma

anandhalagarasa
Path Finder

So kindly help on this request.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

You have edited your question to be completely useless in any context. Why did you do that?

It is also bad form to down vote a response that is not incorrect, even if it doesn't directly answer your question. If it is still correct, then you should not down vote an answer.

It is also GOOD form to accept an answer that does answer your question.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...