Splunk Cloud Platform

How to parse jenkins logs?

sarit_s6
Engager

Hello

I'm using Splunk cloud, i have jenkins logs indexed to my system but for some reason breaks

I took an output example and add it to Splunk with the "Add Data" option and there it looks ok but when im searching for the sourcetype it is still broken.

What is the best way to parse jenkins logs ?

this is my sourcetype configuration :

 

[ console_logs ]
CHARSET=UTF-8
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=true
category=Structured
disabled=false
pulldown_type=true

 

and i want it to be shown with the bulks :

 

<time> Started by user
<time> Finished:

 

 

Labels (1)
Tags (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@sarit_s6 - Kindly provide sample raw data and tell how you would like to see the events being broken, so we can help.

 

0 Karma

sarit_s6
Engager
Hello
Thanks for your reply
I cannot attach the real logs but let have an example
The log will start with timestamp so
08:30:23 Started by Sarit Shvartzman
Raw
Raw
Raw
08:32:34 Finished:
I want all of this to be in one event
Instead of as it now that it breaks by raw
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...