Getting Data In

LINE_BREAKER- how to add


How to add the LINE_BREAKER in propd .conf for the below events to get it split to different events . Currently these are comign as combines together 


Path =567 xcss sdsf  

Path = 5673 dvgsdbdv  v

Path = 43343 dvddv 


I tried

LINE_BREAKER = ([\r\n]+)\Path      


But didnt worked 

Labels (1)
0 Karma



with that data there shouldn’t be any needs for anything else than default line breaker. It seems to be an event per line.

Also \P should be just P as those two has totally different meanings.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...