Splunk Dev

json file line break

sarit_s
Communicator

Hello

i have a json log and i cannot figure out how to break the lines correctly

this is how it looks like :
image (1).png

how can i break the lines that each event will be on is own ?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Since you have 4-digit years, would this work better for the break before pattern?

^\d\d(\d\d\D){6}\S

 

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Break on date, set proper time format and time prefix?

0 Karma

sarit_s
Communicator

yes, you can see it is the image attached 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, but I don't see your time format definition. And it's definitely wrong since the time in raw event is different than the event time in splunk.

You could set TIME_PREFIX as well.

0 Karma

sarit_s
Communicator

sarit_s_0-1638706931992.png

as you can see, it consider 2 events as one for some reason

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Since you have 4-digit years, would this work better for the break before pattern?

^\d\d(\d\d\D){6}\S

 

0 Karma

sarit_s
Communicator

thanks

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I still believe there is something not entirely right with your timestamp recognition. True, in the second screenshot the timestamp "seems" to be right. But.

From the time format you're using, I presume you're somewhere in the US and your local timezone is not GMT. Your event's timestamp is GMT, so...

Anyway, if your logs are reporting time in GMT when they should do in your local time, you have another problem to resolve before you hit some issues with time inconsistency later on.

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...