Getting Data In

multiple breaks

akarandjeff
New Member

Is there a way to break by timestamp and by a pattern? Some of my lines have a timestamp and the timestamp filtering works for them, but globs my non-timestamp lines together. Other lines have a common pattern and using BREAK_ONLY_BEFORE works for them, but globs the timestamp lines together. I need to have my cake and eat it too and would like to be able to filter by both.

Tags (1)
0 Karma

hexx
Splunk Employee
Splunk Employee

If your goal is for each line to be indexed as one event, you can simply specify:

SHOULD_LINEMERGE = false

If you want to event-break on time stamps and on another pattern, a simple way to do this is to define BREAK_ONLY_BEFORE with two patterns:

BREAK_ONLY_BEFORE = (pattern1|pattern2)

...where pattern1 matches your time stamps and pattern2 matches the other desired event-breaking string.

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...