Splunk Search

How do I break into multiple events just by space?

Kitteh
Path Finder

I want the one event in the picture to be broken into many events with the spaces in between. How do I do so with props.conf ?

Heres what i tried in my props.conf i tried "LINE_BREAKER = \s" and "LINE_BREAKER = [\s]"
[daemontest]
LINE_BREAKER = ([\s]+)
SHOULD_LINEMERGE = false

alt text

0 Karma
1 Solution

Kitteh
Path Finder

This has been fixed by adding the parameter "BREAK_ONLY_BEFORE=\s"

[daemontest]
LINE_BREAKER = ([\s]+)
BREAK_ONLY_BEFORE =\s
SHOULD_LINEMERGE = false

Above is my parameters used just by splitting events with space.

View solution in original post

0 Karma

Kitteh
Path Finder

This has been fixed by adding the parameter "BREAK_ONLY_BEFORE=\s"

[daemontest]
LINE_BREAKER = ([\s]+)
BREAK_ONLY_BEFORE =\s
SHOULD_LINEMERGE = false

Above is my parameters used just by splitting events with space.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Are you configuring props.conf on the splunk instance that parses your event stream? That would be either your indexer, or a heavy forwarder you may have in your data ingest path.

0 Karma

Kitteh
Path Finder

I am using universal forwarder

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Then your parsing settings need to go on the indexer as the UF does not do any event parsing.

0 Karma

jhigginsmq
Path Finder

"LINE_BREAKER = ([\s]+)" with "SHOULD_LINEMERGE=false" should work, and it works for me after mocking up a similar example and using the preview feature of "Add Data".

Are you sure those settings are being applied, i.e. are you restarting/refreshing Splunk after editing props.conf?

0 Karma

Kitteh
Path Finder

Yes i've restart everytime i finished editing props.conf

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

See above, these settings have no effect on the UF, they need to go on the indexer, which is where the event parsing happens.
All the forwarder sees are 64KB chunks of data read from a monitored file or received on a network input.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...