Getting Data In

Line Breaking

vijreddy30
Loves-to-Learn Everything

vijreddy30_0-1721056055125.png

The above screen shot Blue color line event into one Event and above Blue color lines in to single event 

please provide line break event queries.

 

Labels (1)
0 Karma

vijreddy30
Loves-to-Learn Everything

Hi Team,

 

04/06/2024;10:08:36;Control;Machine ON
04/06/2024;10:05:39;Others;Start sample (D) ST 2 795 x1000
04/06/2024;10:05:36;Others;Sampling end ST 1
04/06/2024;10:00:25;Others;Start sample (D) ST 1 781 x1000
04/06/2024;09:55:33;Operator;Operator level: 0 -> 6 UP23477

After that break the event, I written regex like  
^\d{2}\/\d{2}\/\d{4};\d{2}:\d{2}:\d{2};Operator;Operator\slevel:\s0\s->\s+6\s+\w+

but not break the event , please help me the regex query

0 Karma

PickleRick
SplunkTrust
SplunkTrust

LINE_BREAKER must contain a capture group. Everything before capture group is considered "previous event", capture group is treated as event breaker _and is removed from your data_ and everything after the capture group is part of the "next event".

Also - you still didn't say what constitutes a new event in your example.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

And how would you tell one event from another? Specify what makes a line be a start of a new event.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @vijreddy30 

the props.conf is needed to understand the line breaking. 

then only the it can be troubleshooted, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

vijreddy30
Loves-to-Learn Everything

Thanks for Update 

 

04/06/2024;09:55:33;Operator;Operator level: 0 -> 6 EP78543 line break Before and after  regex query

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Again - what in this event should tell Splunk that it's a new event?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...