Getting Data In

Configure BREAK_ONLY_BEFORE

Azwaliyana
Path Finder

I just want to configure BREAK_ONLY_BEFORE. When I save the source type, it automatically adds LINE_BREAKER. I do not want the LINE_BREAKER to be there as it will remove the regex that I have specified in BREAK_ONLY_BEFORE. I have done many things. 

I want it to be like this.

Azwaliyana_0-1635827337188.png

 

But when I save it, Splunk automatically add the regex that I have specified for BREAK_ONLY_BEFORE as LINE_BREAKER. And the result is like this. Splunk remove the pg-2

Azwaliyana_1-1635827483476.png

 

What should I do to keep my regex not being removed by Splunk but I want it to split into another event?

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

How are you saving the settings?  I've never seen Splunk automatically add LINE_BREAKER before.  What version of Splunk are you using?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Azwaliyana
Path Finder

I click on Save As button that appears here which is for the source type after uploading the file. 

Azwaliyana_0-1636517376531.png

 

Do you have any solutions for this? I use Splunk 8.1.3

 

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...