Our application has a very readable, but quite unindexable format. Currently, its coming in as multiple lines, which is making my search results a bear to deal with. The format looks like this:
Entering:
Client:ClientCompanyName
LoggedInUser:me@me.com
Class:SurveyDAO
Method:isAdminUser(me@me.com)
StartTime: 2015-01-30 00:54:44 678
Query:select adminFlag from Accounts where id= ?
EndTime:2015-01-30 00:54:44 990
Anyone provide some help in defining a decent file input for that?
You need put configuration similar to below in props.conf against the sourcetype
props.conf
[sourcetype]
SHOULD_LINEMERGE=TRUE
BREAK_ONLY_BEFORE = Entering:
TIME_FORMAT = %Y-%m-%d %H:%M:%S %3N
MAX_TIMESTAMP_LOOKAHEAD = 500
TIME_PREFIX = StartTime:
Note: I have not tested it and it should work fine.
The above configure merges the multi lines event into single line and break the individual event at "Entering:"
You need put configuration similar to below in props.conf against the sourcetype
props.conf
[sourcetype]
SHOULD_LINEMERGE=TRUE
BREAK_ONLY_BEFORE = Entering:
TIME_FORMAT = %Y-%m-%d %H:%M:%S %3N
MAX_TIMESTAMP_LOOKAHEAD = 500
TIME_PREFIX = StartTime:
Note: I have not tested it and it should work fine.
The above configure merges the multi lines event into single line and break the individual event at "Entering:"
Worked like a charm!!! Thanks!