Splunk Search
Highlighted

How to break events as Every Line

Communicator

Hi All,

What's the appropriate regex for event break Every Line? Is my props.conf correct?

[index_name]
LINE_BREAKER = ([\r\n]+)
0 Karma
Highlighted

Re: How to break events as Every Line

Builder

hi there, yes, that is correct.
However the stanza name should not be an index name but a sourcetype name.

Also, you could use
SHOULD_LINEMERGE = false

more info here: http://docs.splunk.com/Documentation/Splunk/6.5.3/Admin/Propsconf

View solution in original post

Highlighted

Re: How to break events as Every Line

Legend

Hi dantimola
to have each event in one line use

SHOULD_LINEMERGE = false

I suggest, before logs indexing, try to index a test copy of your logs using the web extractor (inserting them in a test index), in this way, you can build your props.conf by web interface and see every configuration (timestamp, line break, etc...).
Bye.
Giuseppe

0 Karma