I would like to break some lines into mutliple events.
The break condition is the time, as you can see below in bold in the log file:
[10:27:21.937] DEBUG [RequestStatusTask] [c.s.t.p.a.c.d.p.DataPrinterWrapper] [onSequenceStatusChanged:758] printer 1 :Sequence State : READY / READY
[10:27:22.500] DEBUG [AskCodeTask] [c.s.t.p.a.c.d.p.DataPrinterWrapper]
I have configured the props.conf, but it doesn't work:
BREAK_ONLY_BEFORE = [\d\d:\d\d:\d\d.\d\d\d]
Thanks for your help.
I think you would be better defining the timestamp and telling splunk to break only before a time stamp.
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE_DATE = true
TIME_PREFIX = \[
TIME_FORMAT = %H:%M:%S.%3N
your regex matches not only the time string but also some . and numbers later. try the regex without the [ ] eq BREAK_ONLY_BEFORE = \d\d:\d\d:\d\d.\d\d\d this should match only your time string.
BREAK_ONLY_BEFORE = \d\d:\d\d:\d\d.\d\d\d