Getting Data In

How to configure Splunk to prevent grouping events when the timestamp is identical?

jscraig2006
Communicator

I am having an issue with the time stamp on one of my apps. They will group together if the time stamp is identical in the event.

Example:

Jun 7 17:37:31
Jun 7 17:37:31

However, they are separate events.

But as soon as the time stamp changes, the event is separated. I am currently using in my props.conf file BREAK_ONLY_BEFORE = ^(?<Month>\w+\s+\d+\s+\d+:\d+:\d+)

Any suggestions? Thanks in advanced

0 Karma
1 Solution

woodcock
Esteemed Legend

Try this instead:

TIME_PREFIX=^
TIME_FORMAT = %b %-d %H:%M:%s
BREAK_ONLY_BEFORE_DATE = true
SHOULD_LINEMERGE = false

View solution in original post

woodcock
Esteemed Legend

Try this instead:

TIME_PREFIX=^
TIME_FORMAT = %b %-d %H:%M:%s
BREAK_ONLY_BEFORE_DATE = true
SHOULD_LINEMERGE = false

jscraig2006
Communicator

Thanks woodcock. I placed the above change in the props.conf but the events are still grouping:

6/8/16
10:42:32.000 AM
Jun  8 10:42:32 x.x.x.x CounterACT[2561]: NAC Policy Log: Source: x.x.x.x, Rule: , Details: HPS is going to execute the following command "fs_user.vbs  "
Jun  8 10:42:32 x.x.x.x CounterACT[2561]: NAC Policy Log: Source: x.x.x.x, Rule: , Details: HPS is going to execute the following command "fs_NBTDomain.exe  "
0 Karma

jscraig2006
Communicator

After reindexing and letting it cook, the events are now separated. Thanks again!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...