Hi,
I am new to splunk. I am trying to make my logging message format good.
I have log message with newline or carriage return not sure which one but when I try to replace it using
rex field=message mode=sed "s/^[\r\n]+//g" it does not work, Any suggestions? I am not sure if there are any spaces or white spaces but I also tried with s/^/S*[\r\n]+//g
Message:
Line1
Line2
Line3
Expected :
Line1
Line2
Line3
Your sed matches to [\r\n] at the beginning of the field - could it be at the end? Also, are these 3 instance of the message field or multi-line with the same message instance?