Getting Data In

How to break my events?

chintan_shah
Path Finder

Hi,
i am trying to break the event which we receive from our hand held devices into separate events but its not working properly.
The logs doesn't have any LINE BREAKER and i am using /msg> as delimiter but its not working.
Can some one help me in breaking this event?

Sample Logs:

0 Karma
1 Solution

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19
0 Karma

chintan_shah
Path Finder

Thanks @somesoni2.
It worked but the end of the event is looking as < instead of

PDT Socket Created642949672951<

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/03/30 09:41:05'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>6</v></z><z><v n='Socket Handle'>4294967295</v></z><z><v n='(logs removed)'>1</v></z></b><
0 Karma

somesoni2
Revered Legend

It's actually removing string in first brackets in LINE_BREAKER. If you need that you can use below,

[yoursourcetype]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=(\<msg)
 TIME_PREFIX=d='
 TIME_FORMAT=%Y/%m/%d %H:%M:%S
 MAX_TIMESTAMP_LOOKAHEAD=19
 SEDCMD-addheader = s/^(.+)/<msg \1/
0 Karma

chintan_shah
Path Finder

Thanks Somesoni2. It worked.

0 Karma

somesoni2
Revered Legend

You're missing sample logs here.

0 Karma

chintan_shah
Path Finder

Hi
Please find the sample log
PDT Socket Created2214294967295Extracted PDT Request

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>221</v></z><z><v n='Socket Handle'>4294967295</v></z></b></msg><msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='FetchRequest()'/><i>Extracted PDT Request</i></msg>
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...