Getting Data In

How to break my events?

chintan_shah
Path Finder

Hi,
i am trying to break the event which we receive from our hand held devices into separate events but its not working properly.
The logs doesn't have any LINE BREAKER and i am using /msg> as delimiter but its not working.
Can some one help me in breaking this event?

Sample Logs:

0 Karma
1 Solution

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19
0 Karma

chintan_shah
Path Finder

Thanks @somesoni2.
It worked but the end of the event is looking as < instead of

PDT Socket Created642949672951<

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/03/30 09:41:05'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>6</v></z><z><v n='Socket Handle'>4294967295</v></z><z><v n='(logs removed)'>1</v></z></b><
0 Karma

somesoni2
Revered Legend

It's actually removing string in first brackets in LINE_BREAKER. If you need that you can use below,

[yoursourcetype]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=(\<msg)
 TIME_PREFIX=d='
 TIME_FORMAT=%Y/%m/%d %H:%M:%S
 MAX_TIMESTAMP_LOOKAHEAD=19
 SEDCMD-addheader = s/^(.+)/<msg \1/
0 Karma

chintan_shah
Path Finder

Thanks Somesoni2. It worked.

0 Karma

somesoni2
Revered Legend

You're missing sample logs here.

0 Karma

chintan_shah
Path Finder

Hi
Please find the sample log
PDT Socket Created2214294967295Extracted PDT Request

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>221</v></z><z><v n='Socket Handle'>4294967295</v></z></b></msg><msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='FetchRequest()'/><i>Extracted PDT Request</i></msg>
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...