Getting Data In
Highlighted

How do I edit my props.conf to break multiline events?

Engager

Hello;

I found a problem breaking multiline events in Splunk. I need to break events that have this format:

Events: {"ext, "aaaaaaaaaaaaaaaaaaaaa","":"2"}< >{""ext, "aaaaaaaaaaaaaaaaaaaaa","":"3"}

In the props.conf file, I added these lines, but it's not breaking those events:

[stash]
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = false
BREAK_ONLY_AFTER = (}< >)
SHOULD_LINEMERGE = TRUE

I will appreciate all your help!

Thank you

0 Karma
Highlighted

Re: How do I edit my props.conf to break multiline events?

SplunkTrust
SplunkTrust

BREAKONLYAFTER is not a valid attribute. Do you mean BREAKONLYBEFORE or MUSTBREAKAFTER?
You've specified the SHOULD_LINEMERGE attribute twice. The last instance is the one that will be used. Consider this stanza:

[stash]
LINE_BREAKER = ([\r\n]+)|(< >)
SHOULD_LINEMERGE = false
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

Highlighted

Re: How do I edit my props.conf to break multiline events?

Engager

Thank you very much , by adding this lines i can break this envents .

0 Karma