Getting Data In

Event breaking does not work for SMS debug and SMPP debug logs

Sujithkumarkb
Observer

Hi ,

I am trying to break events which are merging for SMS and SMPP logs.

only the events with binary codes are breaking and rest are still merging.Can anyone advice how I can break events here.

Props I am using is as below

KV_MODE = none
BREAK_ONLY_BEFORE = \d{2}:\d{2}:\d{2}:\d{3}\s+(\d+\w+)
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = true

and 

KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false 

TIME_FORMAT=%H:%M:%S:%3N

 

09:55:26:008 (000005A0) --IP--  --: WaitForResponseSMPP: SMPP Debug: ioctlsocket failed, no data
09:55:26:935 (000007B8) --IP--  --: WaitForResponseSMPP: SMPP Debug: ioctlsocket failed, no data
09:55:27:347 (000007D0) --IP--  --: WaitForResponseSMPP: SMPP Debug: received a submit message
09:55:27:347 (000007D0) --IP--  <-: 103 byte packet
09:55:27:347 (000007D0) --IP--  <-: 00 00 00 67 00 00 00 04 00 00 00 00 00 05 5E C1 g ^
09:55:27:347 (000007D0) --IP--  <-: 00 00 00 36 30 30 30 30 30 30 34 00 00 00 35 32 60000004 52
09:55:27:347 (000007D0) --IP--  <-: 69 6D 57 52 36 4A 73 2F 69 31 69 41 47 4F 45 4D imWR6Js/i1iAGOEM
09:55:27:347 (000007D0) --IP--  <-: 71 75 6E 52 6E 61 71 qunRnaq

 

SMSDebug log

10:00:11:467 [21] CHECKLF0004###0010\5F7ACFDA.REQ: WAIT
10:00:11:467 [23] CHECKLF0004LF0004###0010\5F7ACFDA.REQ: WAIT
10:00:11:640 [22] VWPRODEGOLF0004###0010\5F7ACFDA.REQ: WAIT
10:00:11:815 [5] ThreadListenForSMPPConnections: Before accept
10:00:11:815 [5] ThreadListenForSMPPConnections: After accept
10:00:11:815 [29] ThreadProcessSMPPConnection: Processing SMPP connection from IP...
10:00:11:908 [28] ThreadProcessSMPPConnection: Releasing SMPP connection from IP
10:00:11:909 [28] WaitForSocketClose: WinSock reported ioctlsocket complete

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...