Hi,
I am trying to index data from a local directory, but the line break is not executing correctly. The expression I am using is ([\ r \ n] +), however, it is indexing me more than 3 events into just one. is there any way to define a line break when you find a certain character? for example, when find ";;;"
Hi @Claudia9308,
to help you, you should share some example of your data.
Anyway, there are some methods to break events that you can find at https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Propsconf#Line_breaking
Ciao.
Giuseppe
Hi
easiest way to test this is set up your own dev instance to your own workstation. Then use Setting -> Add Data -> Monitor -> Files & Directories and test with different parameters.
r. Ismo