Getting Data In

How to break my events?

chintan_shah
Path Finder

Hi,
i am trying to break the event which we receive from our hand held devices into separate events but its not working properly.
The logs doesn't have any LINE BREAKER and i am using /msg> as delimiter but its not working.
Can some one help me in breaking this event?

Sample Logs:

0 Karma
1 Solution

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this for your line breaking configuration

[yoursourcetype]
SHOULD_LINEMERGE=false
LINE_BREAKER=(\/msg\>)*(?=\<msg)
TIME_PREFIX=d='
TIME_FORMAT=%Y/%m/%d %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD=19
0 Karma

chintan_shah
Path Finder

Thanks @somesoni2.
It worked but the end of the event is looking as < instead of

PDT Socket Created642949672951<

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/03/30 09:41:05'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>6</v></z><z><v n='Socket Handle'>4294967295</v></z><z><v n='(logs removed)'>1</v></z></b><
0 Karma

somesoni2
Revered Legend

It's actually removing string in first brackets in LINE_BREAKER. If you need that you can use below,

[yoursourcetype]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=(\<msg)
 TIME_PREFIX=d='
 TIME_FORMAT=%Y/%m/%d %H:%M:%S
 MAX_TIMESTAMP_LOOKAHEAD=19
 SEDCMD-addheader = s/^(.+)/<msg \1/
0 Karma

chintan_shah
Path Finder

Thanks Somesoni2. It worked.

0 Karma

somesoni2
Revered Legend

You're missing sample logs here.

0 Karma

chintan_shah
Path Finder

Hi
Please find the sample log
PDT Socket Created2214294967295Extracted PDT Request

0 Karma

chintan_shah
Path Finder
<msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='CPDTSocket()'/><i>PDT Socket Created</i><b><z><v n='PDTSocket ID'>221</v></z><z><v n='Socket Handle'>4294967295</v></z></b></msg><msg t='status' e='2' d='2017/04/28 14:31:28'><s f='' h='FetchRequest()'/><i>Extracted PDT Request</i></msg>
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...