Getting Data In

Configure BREAK_ONLY_BEFORE

Azwaliyana
Path Finder

I just want to configure BREAK_ONLY_BEFORE. When I save the source type, it automatically adds LINE_BREAKER. I do not want the LINE_BREAKER to be there as it will remove the regex that I have specified in BREAK_ONLY_BEFORE. I have done many things. 

I want it to be like this.

Azwaliyana_0-1635827337188.png

 

But when I save it, Splunk automatically add the regex that I have specified for BREAK_ONLY_BEFORE as LINE_BREAKER. And the result is like this. Splunk remove the pg-2

Azwaliyana_1-1635827483476.png

 

What should I do to keep my regex not being removed by Splunk but I want it to split into another event?

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

How are you saving the settings?  I've never seen Splunk automatically add LINE_BREAKER before.  What version of Splunk are you using?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Azwaliyana
Path Finder

I click on Save As button that appears here which is for the source type after uploading the file. 

Azwaliyana_0-1636517376531.png

 

Do you have any solutions for this? I use Splunk 8.1.3

 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...