Getting Data In

LINE_BREAKER keep the line breaking regex string

season88481
Contributor

Hi team,

I have logs like this:

This is Tom This is Amy This is David This is Ben

I want the line breaking to be like this:

This is Tom
This is Amy
This is David
This is Ben

Here is my LINE_BREAKER config

LINE_BREAKER = (this)

And my result is like:

 is Tom
 is Amy
 is David
 is Ben

So how could I keep the line breaking regex? In my case, the "this"?

Many thanks.
S

0 Karma
1 Solution

season88481
Contributor

I think I can answer my own question. Seems Line breaker needs 1 capturing group. Anything matched in the group will not be indexed.
So I updated the LINE_BREAKER to be:
LINE_BREAKER = (\s)this\s

View solution in original post

0 Karma

season88481
Contributor

I think I can answer my own question. Seems Line breaker needs 1 capturing group. Anything matched in the group will not be indexed.
So I updated the LINE_BREAKER to be:
LINE_BREAKER = (\s)this\s

0 Karma

to4kawa
Ultra Champion

LINE_BREAKER is REGEX
this is not same This

LINE_BREAKER = (?i)(\s)This

Line breaker needs 1 capturing group.
Yes, you are.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...