Getting Data In
Highlighted

How do I edit my props.conf to break multiline events?

Engager

Hello;

I found a problem breaking multiline events in Splunk. I need to break events that have this format:

Events: {"ext, "aaaaaaaaaaaaaaaaaaaaa","":"2"}< >{""ext, "aaaaaaaaaaaaaaaaaaaaa","":"3"}

In the props.conf file, I added these lines, but it's not breaking those events:

[stash]
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = false
BREAK_ONLY_AFTER = (}< >)
SHOULD_LINEMERGE = TRUE

I will appreciate all your help!

Thank you

0 Karma
Highlighted

Re: How do I edit my props.conf to break multiline events?

SplunkTrust
SplunkTrust

BREAKONLYAFTER is not a valid attribute. Do you mean BREAKONLYBEFORE or MUSTBREAKAFTER?
You've specified the SHOULD_LINEMERGE attribute twice. The last instance is the one that will be used. Consider this stanza:

[stash]
LINE_BREAKER = ([\r\n]+)|(< >)
SHOULD_LINEMERGE = false
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

Highlighted

Re: How do I edit my props.conf to break multiline events?

Engager

Thank you very much , by adding this lines i can break this envents .

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.