Splunk Cloud Platform

MultiLine Event - Line Breaker

CarolinaHB
Engager

Hi, 

I have a file with many records but when it is indexed in a single event.

Example:

20859000133104142002020052140014M101000042394286020200521012000136024001R0001400000000000039500111342817111342817211342818311342818300000000011342819911342820800000000011342837310500
2085900013320414208085904142200000000046 20200521012000136024001R0050200000000000000056211344550011344550211344551211344551200000000011344552511344553300000000011344569410500
2085900013330414206085904142200000000047 20200521012000136024001R0050200000000000000056311351275511351275511351276711351276700000000011351278411351279500000000011351293910500

My props.conf file is configured

 

[Prueba]
DATETIME_CONFIG =
LINE_BREAKER = ([\r\n]+)
MAX_TIMESTAMP_LOOKAHEAD = 17
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
TIME_FORMAT = %Y%m%d0%H%M%S%3Q
TIME_PREFIX = ^.{49}
category = Custom
pulldown_type = true
BREAK_ONLY_BEFORE_DATE =
disabled = false

I changed the regex in LINE_BREAKER  by   ^.+\n but it does not work.

archivos1.png

Regards, 

Labels (1)
0 Karma

p_gurav
Champion

Please try with

SHOULD_LINEMERGE = false

 

0 Karma

CarolinaHB
Engager

Hi, I try 

SHOULD_LINEMERGE = false

It doesn't work 

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...