==============================================
**Command: C:\cmd command - xxx..
Started at: 12/04/2017 07:03:02
==============================================
**Command: C:\cmd command - xxx..
Started at: 12/04/2017 07:03:02
==============================================
**Command: Command\xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx...
Started at: 12/04/2017 07:06:03
Command output:
c:># xxxxxxxxxxxxxxxxxxx......
c:>xxxxxxxxxxxxxxxxxxxx
==============================================
**Command: C:\cmd command - xxx..
Started at: 12/04/2017 07:06:25
Individual log entries begin and end with a '====' separator.
Since the timestamp entries are seemless across logs, finished and new log parsing is erratic.
Tried with putting following prop.conf at $SPLUNK_HOME/system/local
[source_type]
LINE_BREAKER = [=]+
BREAK_ONLY_BEFORE_DATE = false
SHOULD_LINEMERGE = true
DATETIME_CONFIG = NONE
MUST_BREAK_AFTER = [=]+
The LINE_BREAKER
attribute needs a capture group to work correctly. Try LINE_BREAKER = ([=\s]+)Command:
or LINE_BREAKER = ()Command:
.
The LINE_BREAKER
attribute needs a capture group to work correctly. Try LINE_BREAKER = ([=\s]+)Command:
or LINE_BREAKER = ()Command:
.