Splunk Search

Merge multiple line to one line with end, start line desire?

nnips
Engager

Hi, I'm have trouble with multiple line in my logs and i have many information dont need in this logs.
So I'm want get some information in this log with start line and end line. Anyone have idea for this ?
Example:

Oracle Database 10g Release 
CPU:
RAM:

Thu Apr 12 12:00:00 2012
LENGTH : '111'
ACTION :[7] 'CONNECT'
DATABASE USER:[1] '/'
PRIVILEGE :[6] 'SYSDBA'
CLIENT USER:[6] 'oracle'
CLIENT TERMINAL:[5] 'pts/1'
STATUS:[1] '0

=> Results:

Thu Apr 12 12:00:00 2012
LENGTH : '111'
ACTION :[7] 'CONNECT'
DATABASE USER:[1] '/'
PRIVILEGE :[6] 'SYSDBA'
CLIENT USER:[6] 'oracle'
CLIENT TERMINAL:[5] 'pts/1'
STATUS:[1] '0

=> Somthing dont need:

Oracle Database 10g Release 
CPU:
RAM:
0 Karma

p_gurav
Champion

Hi

Can you try to add HEADER_FIELD_LINE_NUMBER like this in props.conf:

[your_sourcetype]
HEADER_FIELD_LINE_NUMBER = 4
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...