Splunk Enterprise

Linebreak

uagraw01
Communicator

Hello Guys,

Below is my initial event and i want to break each from the staring of this event. As i tried various attributes in props.conf but no luck to break the event from this line.

I used as of now:

LINE_BREAKER = ^\*{22}\n\w+\s\w+\s\w+\sstart\n\Start\stime\:\s\d{14}

TIME_PREFIX = ^\*{22}\n\w+\s\w+\s\w+\sstart\n\Start\stime\:\s

TIME_FORMAT= %Y%m%d%H%M%S

 

**********************

Windows PowerShell transcript start

Start time: 20210223060505

 

Please suggest me what i did wrong in above props.

Labels (1)
0 Karma

uagraw01
Communicator

@manjunathmeti They suggested, use the add-on which they created and i am able to use Add-on directly in my environment. Is there any other approach to break the lines .

 

SHOULD_LINEMERGE=false
LINE_BREAKER=^[*]+\n[A-Za-z]+\s[A-Za-z]+\s[A-Za-z]+\s[A-Za-z]+\nStart\stime\:\s\d{14}
CHARSET=UTF-8
TIME_FORMAT=%Y%m%d%H%M%S

 

Still it is not breaking

0 Karma

manjunathmeti
Champion

hi @uagraw01,

The regex configured forLINE_BREAKER must contain a capturing group. Also, set SHOULD_LINEMERGE to false. Restart forwarder once you add these configurations in props.conf.

LINE_BREAKER = (\*{22}\n)
TIME_PREFIX = \Start\stime\:\s
TIME_FORMAT= %Y%m%d%H%M%S
SHOULD_LINEMERGE = false

  

If this reply helps you, a like would be appreciated.

0 Karma

uagraw01
Communicator

@manjunathmeti It is still not breaking from the second event start from

 

*********************
Windows PowerShell transcript start
Start time:

Tags (1)
0 Karma

manjunathmeti
Champion

Try this:

LINE_BREAKER = (\*{22}\n\w+\s\w+\s\w+\sstart\n)

Note that this will not add the below lines to your events:
*********************
Windows PowerShell transcript start 

0 Karma

uagraw01
Communicator

@manjunathmeti No luck for this as well

Tags (1)
0 Karma

manjunathmeti
Champion

Can you post some raw data?

Tags (1)
0 Karma

uagraw01
Communicator

@manjunathmeti Below are my raw data

 

Windows PowerShell transcript end
End time: 20210223060514
**********************

**********************
Windows PowerShell transcript start
Start time: 20210209051406

Tags (1)
0 Karma

manjunathmeti
Champion

There is an app developed to consume Windows PowerShell transcript logs:
Check this:
https://github.com/HurricaneLabs/TA-powershell_transcript

It is also there in Splunk base: https://splunkbase.splunk.com/app/4984/#/details

 

If this reply helps you, a like would be appreciated.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!