I just want to configure BREAK_ONLY_BEFORE. When I save the source type, it automatically adds LINE_BREAKER. I do not want the LINE_BREAKER to be there as it will remove the regex that I have specified in BREAK_ONLY_BEFORE. I have done many things.
I want it to be like this.
But when I save it, Splunk automatically add the regex that I have specified for BREAK_ONLY_BEFORE as LINE_BREAKER. And the result is like this. Splunk remove the pg-2
What should I do to keep my regex not being removed by Splunk but I want it to split into another event?
How are you saving the settings? I've never seen Splunk automatically add LINE_BREAKER before. What version of Splunk are you using?
I click on Save As button that appears here which is for the source type after uploading the file.
Do you have any solutions for this? I use Splunk 8.1.3