Getting Data In

Line Breaking

vijreddy30
Loves-to-Learn Everything

vijreddy30_0-1721056055125.png

The above screen shot Blue color line event into one Event and above Blue color lines in to single event 

please provide line break event queries.

 

Labels (1)
0 Karma

vijreddy30
Loves-to-Learn Everything

Hi Team,

 

04/06/2024;10:08:36;Control;Machine ON
04/06/2024;10:05:39;Others;Start sample (D) ST 2 795 x1000
04/06/2024;10:05:36;Others;Sampling end ST 1
04/06/2024;10:00:25;Others;Start sample (D) ST 1 781 x1000
04/06/2024;09:55:33;Operator;Operator level: 0 -> 6 UP23477

After that break the event, I written regex like  
^\d{2}\/\d{2}\/\d{4};\d{2}:\d{2}:\d{2};Operator;Operator\slevel:\s0\s->\s+6\s+\w+

but not break the event , please help me the regex query

0 Karma

PickleRick
SplunkTrust
SplunkTrust

LINE_BREAKER must contain a capture group. Everything before capture group is considered "previous event", capture group is treated as event breaker _and is removed from your data_ and everything after the capture group is part of the "next event".

Also - you still didn't say what constitutes a new event in your example.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

And how would you tell one event from another? Specify what makes a line be a start of a new event.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @vijreddy30 

the props.conf is needed to understand the line breaking. 

then only the it can be troubleshooted, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

vijreddy30
Loves-to-Learn Everything

Thanks for Update 

 

04/06/2024;09:55:33;Operator;Operator level: 0 -> 6 EP78543 line break Before and after  regex query

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Again - what in this event should tell Splunk that it's a new event?

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...