Getting Data In

How to break events at the hex message delimiter?

Contributor

I have to break events based on the hex message delimiter. When I ingest data into Splunk, it is showing as letter 'x' or whitespace between events. How do I break events at the hex message delimiter?

0 Karma

Splunk Employee
Splunk Employee

Hi ankithreddy777,

I think you can try the following in props.conf:

FIELD_DELIMITER =
* Tells Splunk which character delimits or separates fields in the specified file or source.
* This attribute supports the use of special characters.

Hope it helps. Thanks!
Hunter

0 Karma

Super Champion

Probably 'REPORT' in props.conf and 'DELIMS' in transforms.conf.
More information would be nice.

0 Karma

SplunkTrust
SplunkTrust

Sample entries please..