Hi Everyone,Could you please help me break below events
Expected Events:
Subject : ABCD
FriendlyName : ABCD
Issuer : ABCD
Thumbprint : 3CBB2CACD16
NotAfter : 2025
Expires in (Days) : 0
ForSplunk : Break
Events which is getting received:
NotAfter : 2025
Expires in (Days) : 0
ForSplunk : Break
Subject : ABCD
FriendlyName :ABCD
Issuer : ABCD
Thumbprint :3CBB2CACD16
Subject : ABCD
FriendlyName :ABCD
Issuer : ABCD
Thumbprint : 3CBB2CACD16
NotAfter : 2025
Expires in (Days) : 68
ForSplunk : Break
I want my Events to break after FOR SPLUNK : BREAK but its creating issue for some of the events and not for all.I dont know why its working in some cases and not working in some of the cases.
This is there in my props.conf
[MY-SOURCETYPE]
DATETIME_CONFIG =
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = custom
pulldown_type = 1
TIME_FORMAT = %Y-%m-%d_%H:%M:%S_%p
SHOULD_LINEMERGE = true
MUST_BREAK_AFTER = Break
disabled = false
I tried the given props.conf but no luck 😞
The events are not breaking after BREAK
Any suggestion further would be appreaciated . Thanks
Try using LINE_BREAKER to break events before "SUBJECT" (the apparent start of an event).
[MY-SOURCETYPE]
DATETIME_CONFIG =
LINE_BREAKER = ([\r\n]+)SUBJECT
NO_BINARY_CHECK = true
category = custom
pulldown_type = 1
TIME_FORMAT = %Y-%m-%d_%H:%M:%S_%p
SHOULD_LINEMERGE = false
disabled = false
You have TIME_FORMAT specified, but I don't see TIME_PREFIX. They usually go together. Nor do I see a timestamp in the sample events so perhaps TIME_FORMAT is not needed.
Thanks @richgalloway for your response
However I have timestamp in my sample events . PFA images for more clear picture
Could you please let me know what would be the TIME_PREFIX in this case then.
I still do not see a timestamp in the events. Splunk has assigned a value to _time for each event, but that does not mean the raw data contains a time.