Getting Data In

XML Data Line Breaking on DateTime tag

ekenne06
Path Finder

Here is my data normally.

2021-01-26 00:00:44.2885 [INFO] SIXPACService.SplunkForwarder.SplunkWriter Attempting to Splunk Message from SITA:
<?xml version="1.0" encoding="utf-8"?>
<DCNSMessage>
  <ID>SIXPAC</ID>
  <RType>14</RType>
  <DateTime>2021-01-26T00:00:35Z</DateTime>
  <ActiveLink>
    <StartDateTime>2021-01-25T23:50:00Z</StartDateTime>
    <StopDateTime>2021-01-26T00:00:00Z</StopDateTime>
    <LocationActive>
      <Location>S-SLC01</Location>
      <Active>0</Active>
    </LocationActive>
  </ActiveLink>
</DCNSMessage>

 

for some reason when the data gets indexed, it's line breaking, so I only get the following data:

2021-01-26 00:00:44.2885 [INFO] SIXPACService.SplunkForwarder.SplunkWriter Attempting to Splunk Message from SITA:
<?xml version="1.0" encoding="utf-8"?>
<DCNSMessage>
  <ID>SIXPAC</ID>
  <RType>14</RType>

Any idea on why it's breaking at the DateTime tag? 

Labels (3)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @ekenne06,

Splunk breaks events when it finds a timestamp by default. You should set timestamp like below;

[your_sourcetype]
TIME_PREFIX = ^
TIMEFORMAT = %Y-%m-%d %H:%M:%S.%4Q

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

ekenne06
Path Finder

so I tried that and it's still breaking at that spot. I did a btool props --debug . Will update if I find anything there. Currently messing around with a few props.conf settings

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...