Getting Data In
Highlighted

hot to merge multiple lines into a single event?

Path Finder

hi guys,

i am trying to merge these lines into a event

so far i tried

[cycledata]
EVENTBREAKER = (CycleDataTask finished)
SHOULD
LINEMERGE = false

i got block of lines starting with CycleDataTask started and finishing with CycleDataTask finished and i want to group them into a single event for each started finished.

and MUST BREAK AFTER same regex

these is an example:

2019-05-09 13:29:02.3975 INFO CycleData - CycleDataTask started ________________________________________________________
2019-05-09 13:29:06.3746 INFO CycleData - Pool has NEW TICKETS:-> =
2019-05-09 13:29:06.3746 INFO CycleData - Pool has NEW TICKETS: ->
2019-05-09 13:29:06.3746 INFO CycleData - Pool has NEW TICKETS: -> 
2019-05-09 13:29:06.3746 INFO CycleData - Pool has NEW TICKETS: -> 
2019-05-09 13:29:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 13:29:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 13:29:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 13:29:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 13:29:06.8166 INFO CycleData - CycleDataTask finished _______________________________________________________

thank you

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

SplunkTrust
SplunkTrust

Is the example a single event you want to break into multiple events or multiple events you want to make into a single event?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Path Finder

the example has been edited, and like that seems just one long line, instead i have multiple lines which i want to merge in a single event

it should start here:

2019-05-09 13:29:02.3975 INFO CycleData - CycleDataTask started ________________________________________________________

and finish here:

2019-05-09 13:29:06.8166 INFO CycleData - CycleDataTask finished _______________________________________________________

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Builder

Hi

Just check if you gave (EVENTBREAKER) instead of LINEBREAKER attribute

[cycledata]
LINEBREAKER = (CycleDataTask finished)
SHOULD
LINEMERGE = false

the above should work

Thanks

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Path Finder

no it does not work

i almost find a solution adding the example in data file but now it cuts off the word 'finished' which i use as regex. and of course i need it in.

(finished)

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Super Champion

For sample data

2019-05-09 14:41:02.3975 INFO CycleData - CycleDataTask started
2019-05-09 14:41:06.3746 INFO CycleData - Pool has NEW TICKETS:-> 
2019-05-09 14:41:06.3746 INFO CycleData - Pool has NEW TICKETS: ->
2019-05-09 14:41:06.3746 INFO CycleData - Pool has NEW TICKETS: ->
2019-05-09 14:41:06.3746 INFO CycleData - Pool has NEW TICKETS: ->
2019-05-09 14:41:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 14:41:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 14:41:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 14:41:06.8166 INFO CycleData - Pool has been updated succesfully.
2019-05-09 14:41:06.8166 INFO CycleData - CycleDataTask finished

Please find solution

[cycledata]
LINE_BREAKER = CycleDataTask finished([\r\n]+)
SHOULD_LINEMERGE = false

cheers

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Path Finder

this does not work

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Super Champion

eh? Can you please verify if the sample data is like above?
Your example had all lines merged already, so no settings required. I have split that into individual lines

Please put your sample data again in a formatted way as it exactly occurs in your file (not in Splunk)

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Path Finder

check now please

reading again my message i was not very clear, i edited it.

0 Karma
Highlighted

Re: hot to merge multiple lines into a single event?

Path Finder

i think there is something going on with my cluster, if i upload a txt sample, and i add the regex (finished) it merges it almost fine, but then, when i add to props.conf does not work at all.

0 Karma