Getting Data In

How to break my events?

chintan_shah
Path Finder

Hi,
i am trying to break the event which we receive from our hand held devices into separate events but its not working properly.
The logs doesn't have any LINE BREAKER and i am using /msg> as delimiter but its not working.
Can some one help me in breaking this event?

Sample Logs:

0 Karma
1 Solution

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19
0 Karma

chintan_shah
Path Finder

Thanks @somesoni2.
It worked but the end of the event is looking as < instead of

PDT Socket Created642949672951<

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/03/30 09:41:05'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>6</v></z><z><v n='Socket Handle'>4294967295</v></z><z><v n='(logs removed)'>1</v></z></b><
0 Karma

somesoni2
Revered Legend

It's actually removing string in first brackets in LINE_BREAKER. If you need that you can use below,

[yoursourcetype]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=(\<msg)
 TIME_PREFIX=d='
 TIME_FORMAT=%Y/%m/%d %H:%M:%S
 MAX_TIMESTAMP_LOOKAHEAD=19
 SEDCMD-addheader = s/^(.+)/<msg \1/
0 Karma

chintan_shah
Path Finder

Thanks Somesoni2. It worked.

0 Karma

somesoni2
Revered Legend

You're missing sample logs here.

0 Karma

chintan_shah
Path Finder

Hi
Please find the sample log
PDT Socket Created2214294967295Extracted PDT Request

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>221</v></z><z><v n='Socket Handle'>4294967295</v></z></b></msg><msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='FetchRequest()'/><i>Extracted PDT Request</i></msg>
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...