Splunk Cloud Platform

Line breaking issue

jackin
Path Finder

Hello

Need some help on below issue.

05-11-2023 07:01:23:156 -0400 ERROR LineBreakingProcessor [1956104 parsing_3] - Line breaking regex has no capturing groups: ^\{ - data_source="D:\Apps.......TXT", .....

My Props :

LINE BREAKER=^\{

NO BINARY CHECK-true

BREAK ONLY_BEFORE=^\{

CHARSET=UTF-8

disabled=false

KV MODE=json

MAX TIMESTAMP LOOKAHEAD=70

TIME PREFIX=timeStamplevtime"\: \s*" 

TIME FORMAT=%Y-%m-%dT%I:%M:%S

TRUNCATE=999999

 

Sample logs :

{

"maexUniqueld": "414D51204D4532352020202020202020B3A95C64016F0040",

"mgexEventCommon": {

"examgr": "ME25",

"exreason": "CHLSTPU",

"extype": "CHANNEL",

"evobjname": "DIRECT.TCP",

"exobjtype": "CHANNEL",

"evuserid":"",

"summary": "Channel - Stopped by User - Channel:DIRECT.TCP",

"cfbcmd": 46,

"cfhreason": 2279,

"extime": "2023-05-11T08:39:23Z",

"extimesecs": 1683794363

},

"mgexData": {

"channe

l": "DIRECT.TCP",

"csnqual": 10

}

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...