Getting Data In

How to configure props.conf to parse timestamps for two different types of events?



I have a feed that has two different types of events and need to grab them both. Not sure how to do's a sample:

Tracking [].
The current time is 6/14/2016 1:25:29 PM.
13:25:29 d:-00.0000359s o:-00.0204019s  [                           *                           ]
13:26:29 d:-00.0000379s o:-00.0215103s  [                           *                           ]
13:27:29 d:-00.0000370s o:-00.0224686s  [                           *                           ]
Tracking [].
The current time is 6/14/2016 1:41:12 PM.
13:41:12 d:-00.0000390s o:+00.1655246s  [                           *                           ]
13:42:12 d:-00.0000452s o:+00.1666010s  [                           *                           ]
13:43:12 d:-00.0000363s o:+00.1684723s  [                           *                           ]
13:44:12 d:-00.0000391s o:+00.1697982s  [                           *                           ]

I want to grab the first two lines as one event, using the second line's timestamp, and grab the ones below as single line events, using that timestamp and then do the same as they appear.


Here's a props.conf sourcetype definition that does that...



SHOULD_LINEMERGE set to true so Splunk considers multiline events
LINE_BREAKER is set to either carriage return (\r) or newline (\n) to cover different line break encoding
BREAK_ONLY_BEFORE further restricts the line breaking to only occur when the regex pattern occurs after the newline

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...