Getting Data In

LINE_BREAKER- how to add


How to add the LINE_BREAKER in propd .conf for the below events to get it split to different events . Currently these are comign as combines together 


Path =567 xcss sdsf  

Path = 5673 dvgsdbdv  v

Path = 43343 dvddv 


I tried

LINE_BREAKER = ([\r\n]+)\Path      


But didnt worked 

Labels (1)
0 Karma



with that data there shouldn’t be any needs for anything else than default line breaker. It seems to be an event per line.

Also \P should be just P as those two has totally different meanings.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...