Getting Data In

Error of Data Quality

jackin
Path Finder

Hello
Need some help to fix the below error

03-14-2014 17:11:49.108 -0300 ERROR LineBreakingProcessor - Line breaking regex has no capturing groups: ^\{ - data_source=..........

My props:

[source::abc]
disabled=false
pulldown_type=true
TRUNCATE=25000
TIME_PREFIX="timestamp"\s* :\s*"
LINE_BREAKER=^\{ BREAK_ONLY_BEFORE=^{
CHARSET=UTF-8
SHOULD_LINEMERGE=true
category=Custom
pulldown=true

Sample log:

 

{

"maexUniqueld": "414D51204D4532352020202020202020B3A95C64016F0040",

"mgexEventCommon": {

"examgr": "ME25",

"exreason": "CHLSTPU",

"extype": "CHANNEL",

"evobjname": "DIRECT.TCP",

"exobjtype": "CHANNEL",

"evuserid":"",

"summary": "Channel - Stopped by User - Channel:DIRECT.TCP",

"cfbcmd": 46,

"cfhreason": 2279,

"extime": "2023-05-11T08:39:23Z",

"extimesecs": 1683794363

},

"mgexData": {

"channel": "DIRECT.TCP",

"csnqual": 10

}

Labels (3)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...