Getting Data In

Can you define a line break when you find a certain character?

Claudia9308
New Member

Hi,

I am trying to index data from a local directory, but the line break is not executing correctly. The expression I am using is ([\ r \ n] +), however, it is indexing me more than 3 events into just one. is there any way to define a line break when you find a certain character? for example, when find ";;;"

Labels (2)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Claudia9308,

to help you, you should share some example of your data.

Anyway, there are some methods  to break events that you can find at https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Propsconf#Line_breaking

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

easiest way to test this is set up your own dev instance to your own workstation. Then use Setting -> Add Data -> Monitor -> Files & Directories and test with different parameters.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...