I have a text file as shown below:
(raw text file)
cn=host1:1636,cn=host2:1389,ibm-replicaGroup=default,O=org1
ibm-replicationPendingChangeCount=0
cn=host1:1636,cn=host2:1389,ibm-replicaGroup=default,CN=cn1
ibm-replicationPendingChangeCount=0
Current Date and Time = Mon Jun 29 20:45:00 PDT 2015
When it comes into Splunk it, breaks into two events as shown:
6/29/15 8:50:00.000 PM Current Date and Time = Mon Jun 29 20:50:00 PDT 2015
6/29/15 8:50:00.000 PM cn=host1:1636,cn=host2:1389,ibm-replicaGroup=default,O=org1
ibm-replicationPendingChangeCount=0
cn=host1:1636,cn=host2:1389,ibm-replicaGroup=default,CN=cn1
ibm-replicationPendingChangeCount=0
How do I make this one event like this:
6/29/15 8:50:00.000 PM cn=host1:1636,cn=host2:1389,ibm-replicaGroup=default,O=org1
ibm-replicationPendingChangeCount=0
cn=host1:1636,cn=host2:1389,ibm-replicaGroup=default,CN=cn1
ibm-replicationPendingChangeCount=0
Current Date and Time = Mon Jun 29 20:45:00 PDT 2015
What would be the correct props.conf stanza? Please help.
MAX_TIMESTAMP_LOOKAHEAD=325
SHOULD_LINEMERGE=true
BREAK_ONLY_BEFORE=org1
NO_BINARY_CHECK=true
MAX_TIMESTAMP_LOOKAHEAD=325
SHOULD_LINEMERGE=true
BREAK_ONLY_BEFORE=org1
NO_BINARY_CHECK=true