Splunk Dev

json file line break

sarit_s
Communicator

Hello

i have a json log and i cannot figure out how to break the lines correctly

this is how it looks like :
image (1).png

how can i break the lines that each event will be on is own ?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Since you have 4-digit years, would this work better for the break before pattern?

^\d\d(\d\d\D){6}\S

 

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Break on date, set proper time format and time prefix?

0 Karma

sarit_s
Communicator

yes, you can see it is the image attached 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, but I don't see your time format definition. And it's definitely wrong since the time in raw event is different than the event time in splunk.

You could set TIME_PREFIX as well.

0 Karma

sarit_s
Communicator

sarit_s_0-1638706931992.png

as you can see, it consider 2 events as one for some reason

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Since you have 4-digit years, would this work better for the break before pattern?

^\d\d(\d\d\D){6}\S

 

0 Karma

sarit_s
Communicator

thanks

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I still believe there is something not entirely right with your timestamp recognition. True, in the second screenshot the timestamp "seems" to be right. But.

From the time format you're using, I presume you're somewhere in the US and your local timezone is not GMT. Your event's timestamp is GMT, so...

Anyway, if your logs are reporting time in GMT when they should do in your local time, you have another problem to resolve before you hit some issues with time inconsistency later on.

0 Karma
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...