Dashboards & Visualizations

Event Breaking Catastrophe!

markhvesta
Path Finder

Line Breaking is not functioning correctly for an XML source type.

We want to break between these two elements </result> <result expand

Here is the most recent config:
SHOULD_LINEMERGE=false
LINE_BREAKER=<result\sexpand
BREAK_ONLY_BEFORE=<result\sexpand
BREAK_ONLY_BEFORE_DATE=false
MUST_BREAK_AFTER=\/results>

Does this need to be applied to the indexers or in the props.conf on the forwarder? And if just the forwarder, just on the application/local or also in the system/local?

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

Never use the BREAK_* options; always use LINE_BREAKER like this (you must have a capture group😞

props.conf (on your Indexers/HFs):

SHOULD_LINEMERGE = false
LINE_BREAKER = <\/result>([\r\n\s]*)<result\s+expand

View solution in original post

woodcock
Esteemed Legend

Never use the BREAK_* options; always use LINE_BREAKER like this (you must have a capture group😞

props.conf (on your Indexers/HFs):

SHOULD_LINEMERGE = false
LINE_BREAKER = <\/result>([\r\n\s]*)<result\s+expand
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...