Splunk Cloud Platform

Line breaking issue

jackin
Path Finder

Hello

Need some help on below issue.

05-11-2023 07:01:23:156 -0400 ERROR LineBreakingProcessor [1956104 parsing_3] - Line breaking regex has no capturing groups: ^\{ - data_source="D:\Apps.......TXT", .....

My Props :

LINE BREAKER=^\{

NO BINARY CHECK-true

BREAK ONLY_BEFORE=^\{

CHARSET=UTF-8

disabled=false

KV MODE=json

MAX TIMESTAMP LOOKAHEAD=70

TIME PREFIX=timeStamplevtime"\: \s*" 

TIME FORMAT=%Y-%m-%dT%I:%M:%S

TRUNCATE=999999

 

Sample logs :

{

"maexUniqueld": "414D51204D4532352020202020202020B3A95C64016F0040",

"mgexEventCommon": {

"examgr": "ME25",

"exreason": "CHLSTPU",

"extype": "CHANNEL",

"evobjname": "DIRECT.TCP",

"exobjtype": "CHANNEL",

"evuserid":"",

"summary": "Channel - Stopped by User - Channel:DIRECT.TCP",

"cfbcmd": 46,

"cfhreason": 2279,

"extime": "2023-05-11T08:39:23Z",

"extimesecs": 1683794363

},

"mgexData": {

"channe

l": "DIRECT.TCP",

"csnqual": 10

}

Labels (2)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...