Splunk Search

How to line break raw events

Sailesh6891
Engager

Hi, 

I have a log file on the server which I ingested in splunk through input app where I defined the index , sourcetype and monitor statement in inputs.conf. Log file on the server looks like below:

xyz
asdfoasdf
asfanfafd
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
sdfsdfja
agf[oija[gfojerg
fgoaierr
apodsifa[soigaiga[oiga[dogj
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
sadfnasd;fiasfdoiasndf'i
dfdf
fd
garehaehseht
shse
thse
tjst
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
asdf;nafdsknasdf
asdfknasdfln
asdf;nasdkfnasf
asogja'fja
foj'apogj
aogj
agf

 

When I try searching the log file in splunk, Logs are visible howerver events are not breaking as I expect it to come. I want events to be separated as below

 

Event 1:

xyz
asdfoasdf
asfanfafd
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Event 2:

sdfsdfja
agf[oija[gfojerg
fgoaierr
apodsifa[soigaiga[oiga[dogj

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 

Event 3:


sadfnasd;fiasfdoiasndf'i
dfdf
fd
garehaehseht
shse
thse
tjst

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Event 4:

asdf;nafdsknasdf
asdfknasdfln
asdf;nasdkfnasf
asogja'fja
foj'apogj
aogj
agf

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sailesh6891 ,

did you tried to use LINE_BREKING option in props.conf?

[your-sourcetype]
LINE_BREAKING = :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Ciao.

Giuseppe

0 Karma

Sailesh6891
Engager

No, I have not used LINE_BREAKING option. 

Do I need to create a props.conf under splunk_home$/etc/apps/local/ 

and mention these 2 lines ?i.e [sourcetype] and LINE_BREAKING =  :::::::::::::::::::

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sailesh6891 ,

it's a best practive to create a custom add-on containing all the parsing rules for your data, also because I suppose that there are other parsing rules that you need to add.

but anyway you can also put this two lines in another props.conf.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...