Splunk Search

How to line break raw events

Sailesh6891
Engager

Hi, 

I have a log file on the server which I ingested in splunk through input app where I defined the index , sourcetype and monitor statement in inputs.conf. Log file on the server looks like below:

xyz
asdfoasdf
asfanfafd
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
sdfsdfja
agf[oija[gfojerg
fgoaierr
apodsifa[soigaiga[oiga[dogj
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
sadfnasd;fiasfdoiasndf'i
dfdf
fd
garehaehseht
shse
thse
tjst
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
asdf;nafdsknasdf
asdfknasdfln
asdf;nasdkfnasf
asogja'fja
foj'apogj
aogj
agf

 

When I try searching the log file in splunk, Logs are visible howerver events are not breaking as I expect it to come. I want events to be separated as below

 

Event 1:

xyz
asdfoasdf
asfanfafd
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Event 2:

sdfsdfja
agf[oija[gfojerg
fgoaierr
apodsifa[soigaiga[oiga[dogj

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 

Event 3:


sadfnasd;fiasfdoiasndf'i
dfdf
fd
garehaehseht
shse
thse
tjst

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Event 4:

asdf;nafdsknasdf
asdfknasdfln
asdf;nasdkfnasf
asogja'fja
foj'apogj
aogj
agf

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sailesh6891 ,

did you tried to use LINE_BREKING option in props.conf?

[your-sourcetype]
LINE_BREAKING = :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Ciao.

Giuseppe

0 Karma

Sailesh6891
Engager

No, I have not used LINE_BREAKING option. 

Do I need to create a props.conf under splunk_home$/etc/apps/local/ 

and mention these 2 lines ?i.e [sourcetype] and LINE_BREAKING =  :::::::::::::::::::

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sailesh6891 ,

it's a best practive to create a custom add-on containing all the parsing rules for your data, also because I suppose that there are other parsing rules that you need to add.

but anyway you can also put this two lines in another props.conf.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...