Getting Data In

Multiple lines in a single event CSV

rdgg97
Explorer

Hi.

I have the following CSV entry. The problem is that splunk take events from every line, but i have to merge multiple lines in a single event.

101,102,103

104,105,106

107,108,109
,,,RA,FA,DA
,,,TE,TS,POL

110,111,112

Tags (1)
0 Karma

Kawtar
Path Finder

Hello,

There are other settings you may need to specify in your props.conf.

Make sure SHOULD_LINEMERGE is set to true.

     ## props.conf ##

     SHOULD_LINEMERGE = TRUE

Regards,

0 Karma

Sukisen1981
Champion

how does splunk show the events now and how do you want it?

0 Karma

rdgg97
Explorer

Splunk shows the events as follow:

Event) INFO

1) 101,102,103
2) 104,105,106
3) 107,108,109
4) , , RA, FA, DA
5) , , TE, TS, POL
6) 110,111,112

And I want to splunk take events 3,4 & 5 as one

1) 101,102,103
2) 104,105,106
3) 107,108,109
, , RA, FA, DA
, , TE, TS, POL
6) 110,111,112

0 Karma

Sukisen1981
Champion

try this in your props.conf
Add a new stanza for your sourcetype, make sure to save your sourcetype while uploading the csv as a unique name
[your unique sourcetype]
BREAK_ONLY_BEFORE = ^\d+\s*$
make
SHOULD_LINEMERGE = FALSE, revert back the default settings for SHOULD_LINEMERGE

Kawtar
Path Finder

Hello
You should use this settings you may need to specify in your props.conf.

SHOULD_LINEMERGE = true

0 Karma

rdgg97
Explorer

Thank you. I tried but nothing changed.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...