Splunk Search

Data Onboarding line break at empty lines

inventsekar
SplunkTrust
SplunkTrust

Hi.. 

Spent some one or two hrs, but no luck, hence posting here.. the sample logs:

1.1.1. test log a
1.1.1. test log abc

1.1.2. test log b
1.1.2. test log bcd

one thing - no need to worry about timestamps. 

one log will have around 10 events.
the lines with the starting 1.1.1. should be one event, 1.1.2. should be next event and so on.. 

or simply, the empty lines should break the events. 

please suggest, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Labels (1)
0 Karma
1 Solution

yeahnah
Motivator

Hi @inventsekar 

Give this ago...

 

SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]\s[\r\n]+)

 

 

 Not exactly sure why the \s makes a difference - regex101 says \s matches any whitespace character (equivalent to [\r\n\t\f\v  ]) - but it tested OK when I used it 

yeahnah_0-1684376337450.png

Hope that helps

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

wow, @yeahnah you are a life saver ! thanks a ton! 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

yeahnah
Motivator

FYI - it's the \v metacharacter that makes it work.  From the references I found it means vertical tab or vertical whitespace character, which in this instance would equate to the blank line.

0 Karma

yeahnah
Motivator

Hi @inventsekar 

Give this ago...

 

SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]\s[\r\n]+)

 

 

 Not exactly sure why the \s makes a difference - regex101 says \s matches any whitespace character (equivalent to [\r\n\t\f\v  ]) - but it tested OK when I used it 

yeahnah_0-1684376337450.png

Hope that helps

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...