Getting Data In

How to configure proper line breaking for indexing ftp log files?

shane_berry
Engager

I have some ftp log files that I am indexing and when I search, there will be events that have 275 lines in them instead of one line which is what I want. The lines look like this:

19:00 | 00:00:28.387 | 75   -Sent-> 1004 SSH_FXP_READDIR /Outbound/SON/.
19:00 | 00:00:28.434 | 75   <-Recv- 1004 SSH_FXP_STATUS EOF(1)
19:00 | 00:00:28.434 | 75   -Sent-> 1005 SSH_FXP_CLOSE 
19:00 | 00:00:28.496 | 75   <-Recv- 1005 SSH_FXP_STATUS OK

They have a carriage return and line feed at the end of each line. I have tried the following settings in props.conf with no luck:

SHOULD_LINEMERGE = false
LINE_BREAKER=[\r\n]+ (both escaped)
TIME_PREFIX = |\s (both escaped)
TIME_FORMAT = %H:%M:%S.%3N

Any ideas?

0 Karma
1 Solution

shane_berry
Engager

This is working now with these settings.

View solution in original post

0 Karma

shane_berry
Engager

This is working now with these settings.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...