Archive
Highlighted

How do I break into multiple events just by space?

Path Finder

I want the one event in the picture to be broken into many events with the spaces in between. How do I do so with props.conf ?

Heres what i tried in my props.conf i tried "LINEBREAKER = \s" and "LINEBREAKER = [\s]"
[daemontest]
LINEBREAKER = ([\s]+)
SHOULD
LINEMERGE = false

alt text

0 Karma
Highlighted

Re: How do I break into multiple events just by space?

Path Finder

"LINEBREAKER = ([\s]+)" with "SHOULDLINEMERGE=false" should work, and it works for me after mocking up a similar example and using the preview feature of "Add Data".

Are you sure those settings are being applied, i.e. are you restarting/refreshing Splunk after editing props.conf?

0 Karma
Highlighted

Re: How do I break into multiple events just by space?

Path Finder

Yes i've restart everytime i finished editing props.conf

0 Karma
Highlighted

Re: How do I break into multiple events just by space?

Splunk Employee
Splunk Employee

See above, these settings have no effect on the UF, they need to go on the indexer, which is where the event parsing happens.
All the forwarder sees are 64KB chunks of data read from a monitored file or received on a network input.

0 Karma
Highlighted

Re: How do I break into multiple events just by space?

Splunk Employee
Splunk Employee

Are you configuring props.conf on the splunk instance that parses your event stream? That would be either your indexer, or a heavy forwarder you may have in your data ingest path.

0 Karma

Re: How do I break into multiple events just by space?

Path Finder

I am using universal forwarder

0 Karma
Highlighted

Re: How do I break into multiple events just by space?

Splunk Employee
Splunk Employee

Then your parsing settings need to go on the indexer as the UF does not do any event parsing.

0 Karma
Highlighted

Re: How do I break into multiple events just by space?

Path Finder

This has been fixed by adding the parameter "BREAKONLYBEFORE=\s"

[daemontest]
LINEBREAKER = ([\s]+)
BREAK
ONLYBEFORE =\s
SHOULD
LINEMERGE = false

Above is my parameters used just by splitting events with space.

View solution in original post

0 Karma