Getting Data In

Multiple lines in a single event CSV

rdgg97
Explorer

Hi.

I have the following CSV entry. The problem is that splunk take events from every line, but i have to merge multiple lines in a single event.

101,102,103

104,105,106

107,108,109
,,,RA,FA,DA
,,,TE,TS,POL

110,111,112

Tags (1)
0 Karma

Kawtar
Path Finder

Hello,

There are other settings you may need to specify in your props.conf.

Make sure SHOULD_LINEMERGE is set to true.

     ## props.conf ##

     SHOULD_LINEMERGE = TRUE

Regards,

0 Karma

Sukisen1981
Champion

how does splunk show the events now and how do you want it?

0 Karma

rdgg97
Explorer

Splunk shows the events as follow:

Event) INFO

1) 101,102,103
2) 104,105,106
3) 107,108,109
4) , , RA, FA, DA
5) , , TE, TS, POL
6) 110,111,112

And I want to splunk take events 3,4 & 5 as one

1) 101,102,103
2) 104,105,106
3) 107,108,109
, , RA, FA, DA
, , TE, TS, POL
6) 110,111,112

0 Karma

Sukisen1981
Champion

try this in your props.conf
Add a new stanza for your sourcetype, make sure to save your sourcetype while uploading the csv as a unique name
[your unique sourcetype]
BREAK_ONLY_BEFORE = ^\d+\s*$
make
SHOULD_LINEMERGE = FALSE, revert back the default settings for SHOULD_LINEMERGE

Kawtar
Path Finder

Hello
You should use this settings you may need to specify in your props.conf.

SHOULD_LINEMERGE = true

0 Karma

rdgg97
Explorer

Thank you. I tried but nothing changed.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...