Splunk Enterprise

Linebreak

uagraw01
Builder

Hello Guys,

Below is my initial event and i want to break each from the staring of this event. As i tried various attributes in props.conf but no luck to break the event from this line.

I used as of now:

LINE_BREAKER = ^\*{22}\n\w+\s\w+\s\w+\sstart\n\Start\stime\:\s\d{14}

TIME_PREFIX = ^\*{22}\n\w+\s\w+\s\w+\sstart\n\Start\stime\:\s

TIME_FORMAT= %Y%m%d%H%M%S

 

**********************

Windows PowerShell transcript start

Start time: 20210223060505

 

Please suggest me what i did wrong in above props.

Labels (1)
0 Karma

uagraw01
Builder

@manjunathmeti They suggested, use the add-on which they created and i am able to use Add-on directly in my environment. Is there any other approach to break the lines .

 

SHOULD_LINEMERGE=false
LINE_BREAKER=^[*]+\n[A-Za-z]+\s[A-Za-z]+\s[A-Za-z]+\s[A-Za-z]+\nStart\stime\:\s\d{14}
CHARSET=UTF-8
TIME_FORMAT=%Y%m%d%H%M%S

 

Still it is not breaking

0 Karma

manjunathmeti
Champion

hi @uagraw01,

The regex configured forLINE_BREAKER must contain a capturing group. Also, set SHOULD_LINEMERGE to false. Restart forwarder once you add these configurations in props.conf.

LINE_BREAKER = (\*{22}\n)
TIME_PREFIX = \Start\stime\:\s
TIME_FORMAT= %Y%m%d%H%M%S
SHOULD_LINEMERGE = false

  

If this reply helps you, a like would be appreciated.

0 Karma

uagraw01
Builder

@manjunathmeti It is still not breaking from the second event start from

 

*********************
Windows PowerShell transcript start
Start time:

Tags (1)
0 Karma

manjunathmeti
Champion

Try this:

LINE_BREAKER = (\*{22}\n\w+\s\w+\s\w+\sstart\n)

Note that this will not add the below lines to your events:
*********************
Windows PowerShell transcript start 

0 Karma

uagraw01
Builder

@manjunathmeti No luck for this as well

Tags (1)
0 Karma

manjunathmeti
Champion

Can you post some raw data?

Tags (1)
0 Karma

uagraw01
Builder

@manjunathmeti Below are my raw data

 

Windows PowerShell transcript end
End time: 20210223060514
**********************

**********************
Windows PowerShell transcript start
Start time: 20210209051406

Tags (1)
0 Karma

manjunathmeti
Champion

There is an app developed to consume Windows PowerShell transcript logs:
Check this:
https://github.com/HurricaneLabs/TA-powershell_transcript

It is also there in Splunk base: https://splunkbase.splunk.com/app/4984/#/details

 

If this reply helps you, a like would be appreciated.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...