Getting Data In

How to break events at the hex message delimiter?

ankithreddy777
Contributor

I have to break events based on the hex message delimiter. When I ingest data into Splunk, it is showing as letter 'x' or whitespace between events. How do I break events at the hex message delimiter?

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi ankithreddy777,

I think you can try the following in props.conf:

FIELD_DELIMITER =
* Tells Splunk which character delimits or separates fields in the specified file or source.
* This attribute supports the use of special characters.

Hope it helps. Thanks!
Hunter

0 Karma

lukejadamec
Super Champion

Probably 'REPORT' in props.conf and 'DELIMS' in transforms.conf.
More information would be nice.

0 Karma

somesoni2
Revered Legend

Sample entries please..

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...