Getting Data In

How to configure proper line breaking for indexing ftp log files?

shane_berry
Engager

I have some ftp log files that I am indexing and when I search, there will be events that have 275 lines in them instead of one line which is what I want. The lines look like this:

19:00 | 00:00:28.387 | 75   -Sent-> 1004 SSH_FXP_READDIR /Outbound/SON/.
19:00 | 00:00:28.434 | 75   <-Recv- 1004 SSH_FXP_STATUS EOF(1)
19:00 | 00:00:28.434 | 75   -Sent-> 1005 SSH_FXP_CLOSE 
19:00 | 00:00:28.496 | 75   <-Recv- 1005 SSH_FXP_STATUS OK

They have a carriage return and line feed at the end of each line. I have tried the following settings in props.conf with no luck:

SHOULD_LINEMERGE = false
LINE_BREAKER=[\r\n]+ (both escaped)
TIME_PREFIX = |\s (both escaped)
TIME_FORMAT = %H:%M:%S.%3N

Any ideas?

0 Karma
1 Solution

shane_berry
Engager

This is working now with these settings.

View solution in original post

0 Karma

shane_berry
Engager

This is working now with these settings.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...