Can someone please explain why these steps won't work? XML file that I input in Splunk are one event, like this:
[monitor://c:/to_the_file] Sourcetype = aaa
[aaa] SHOULD_LINEMERGE = false LINE_BREAKER = ([\r\n]*)
I have tried this from Splunk Web (upload file and configured
SHOULD_LINEMERGE = false and
LINE_BREAKER = ([\r\n]*)) and it worked, but when I do it from .conf files, it won't. Any ideas?
And of course, how can I configure date and time to be recognized from Splunk?
Give this a try
[aaa] SHOULD_LINEMERGE = false LINE_BREAKER = ([\r\n]*)(?=\<LOG\>) TIME_PREFIX = DATE\> TIME_FORMAT = %Y%m%d</DATE><TIME>%H%M%S MAX_TIMESTAMP_LOOKAHEAD = 27
Thanks for helping,
ok, we broke logs now with those lines, but the date and time are not recognized from splunk. I have read that I should make datetime.xml file a configure it along with props.conf?