Splunk Dev

json file line break

sarit_s
Communicator

Hello

i have a json log and i cannot figure out how to break the lines correctly

this is how it looks like :
image (1).png

how can i break the lines that each event will be on is own ?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Since you have 4-digit years, would this work better for the break before pattern?

^\d\d(\d\d\D){6}\S

 

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Break on date, set proper time format and time prefix?

0 Karma

sarit_s
Communicator

yes, you can see it is the image attached 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, but I don't see your time format definition. And it's definitely wrong since the time in raw event is different than the event time in splunk.

You could set TIME_PREFIX as well.

0 Karma

sarit_s
Communicator

sarit_s_0-1638706931992.png

as you can see, it consider 2 events as one for some reason

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Since you have 4-digit years, would this work better for the break before pattern?

^\d\d(\d\d\D){6}\S

 

0 Karma

sarit_s
Communicator

thanks

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I still believe there is something not entirely right with your timestamp recognition. True, in the second screenshot the timestamp "seems" to be right. But.

From the time format you're using, I presume you're somewhere in the US and your local timezone is not GMT. Your event's timestamp is GMT, so...

Anyway, if your logs are reporting time in GMT when they should do in your local time, you have another problem to resolve before you hit some issues with time inconsistency later on.

0 Karma
Get Updates on the Splunk Community!

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...

Splunk Answers Content Calendar, June Edition II

Get ready to dive into Splunk Dashboard panels this week! We'll be tackling common questions around ...

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...