Getting Data In

LINE_BREAKER- how to add


How to add the LINE_BREAKER in propd .conf for the below events to get it split to different events . Currently these are comign as combines together 


Path =567 xcss sdsf  

Path = 5673 dvgsdbdv  v

Path = 43343 dvddv 


I tried

LINE_BREAKER = ([\r\n]+)\Path      


But didnt worked 

Labels (1)
0 Karma



with that data there shouldn’t be any needs for anything else than default line breaker. It seems to be an event per line.

Also \P should be just P as those two has totally different meanings.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...