Getting Data In

html event line_break configuration?

karu0711
Communicator
<html><head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="Generator" content="Microsoft Word 15 (filtered medium)"><style> <!-- @font-face {font-family:"Cambria Math"} @font-face {font-family:Calibri} p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:11.0pt; font-family:"Calibri",sans-serif} span.EmailStyle17 {font-family:"Calibri",sans-serif; color:windowtext} .MsoChpDefault {font-family:"Calibri",sans-serif} @page WordSection1 {margin:1.0in 1.0in 1.0in 1.0in} div.WordSection1 {} --> </style></head><body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word"><div class="WordSection1"><p class="MsoNormal"><br>Dear [User],</p><p class="MsoNormal">&nbsp;</p><p class="MsoNormal"><br>I am writing to provide you with an update on the recent test email incident that occurred.<br><br><br><br>If you have any questions or concerns, please do not hesitate to contact our team.<br>Thank you for your attention to this matter.<br><br></p><p class="MsoNormal">Sincerely,<br><br></p><p class="MsoNormal">&nbsp;</p><p class="MsoNormal">&nbsp;</p></div></body></html><div class=""><p class="">Above format I get my body of the email in Splunk body field How do I get this to look like below in Splunk.<br />What should you in Line breaker configuration sourcetype?<br /><br />Dear [User],</p><p class="">&nbsp;</p><p class=""><br />I am writing to provide you with an update on the recent test email incident that occurred.<br /><br /><br /><br />If you have any questions or concerns, please do not hesitate to contact our team.<br />Thank you for your attention to this matter.<br /><br /></p><p class="">Sincerely,<br /><br /></p><p class="">&nbsp;</p><p class="">&nbsp;</p></div>
Labels (3)
Tags (1)
0 Karma

karu0711
Communicator
 

 

 

I want above html email body field to look like below text. how do I configure sourcetype parse the data properly.

 
Dear [User],

&nbsp;


I am writing to provide you with an update on the recent test email incident that occurred.



If you have any questions or concerns, please do not hesitate to contact our team.
Thank you for your attention to this matter.

Sincerely,

&nbsp;

&nbsp;

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...