How can I set the start and end of events in the source selection. To output only my event . I use MUST_BREAK_AFTER and Line breaking and BREAK_ONLY_BEFORE.How to use LINE_BREAKER? For example my event start: main: "number of bytes received" and finish: Send msg to queue.
Generally you do 1 of 2 things; either:
1: Modify the linbreaker to consume all variations of your inter-event garbage (including newlines) with:
LINE_BREAKER=MyRegExForInterEventJunk
SOULD_LINEMERGE = false
2: Allow the junk to be part of the end of each event and tell Splunk were to break
BREAK_ONLY_BEFORE=MyRegExForWhereToBreak
SHOULD_LINEMERGE = true
Generally, the latter is preferable.
This question is impossible to answer. Please give some examples of your data.
Also, usually you use only one of these settings: MUST_BREAK_AFTER, BREAK_ONLY_BEFORE, and LINE_BREAKER.
You don't use all three of them at once, only the setting that works best for your data.