Getting Data In

Can you define a line break when you find a certain character?

Claudia9308
New Member

Hi,

I am trying to index data from a local directory, but the line break is not executing correctly. The expression I am using is ([\ r \ n] +), however, it is indexing me more than 3 events into just one. is there any way to define a line break when you find a certain character? for example, when find ";;;"

Labels (3)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Claudia9308,

to help you, you should share some example of your data.

Anyway, there are some methods  to break events that you can find at https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Propsconf#Line_breaking

Ciao.

Giuseppe

0 Karma

soutamo
SplunkTrust
SplunkTrust

Hi

easiest way to test this is set up your own dev instance to your own workstation. Then use Setting -> Add Data -> Monitor -> Files & Directories and test with different parameters.

r. Ismo

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!