Splunk Search

How to parse an Aide scan log file to display each line?

bcain22
Engager

I am new to Splunk and I am trying to parse an Aide scan log file to display each line. Currently, Splunk just reads all the lines as a single event.  I know I may have to build a regex once I have Splunk reading the file correctly, but currently Splunk isn't extracting the events by the newline character. Sample data below:

bcain22_2-1647895680328.png

 

bcain22_1-1647895288925.png

 

How can I get Splunk to parse each line vs reading the entire file as a single event?

bcain22_0-1647895236764.png

 

 

Labels (1)
0 Karma
1 Solution

bcain22
Engager
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...