Splunk Search

regex help for props.conf BREAK_ONLY_BEFORE option

conner9
Path Finder

So we have a script that runs tests to monitor if a system has changed and the output examples below are the lines I need to break before. This will allow us to easily display the results of the tests. None of the lines of data that include the results have the # preceding them, but they may have a # in the line somewhere.
I am hoping someone might suggest a regex that will allow me to break the event appropriately.

BREAK_ONLY_BEFORE=Regex

Jan 17 15:07:58 hostname.test.com filename.pl # check USB access

Jan 17 15:07:58 hostname.test.com filename.pl # check File name access access
Jan 17 15:07:58 hostname.test.com filename.pl ##### filename.pl #####

Jan 17 15:07:58 hostname.test.com filename.pl ##### filename1.pl #####

Thanks for any thoughts.

0 Karma
1 Solution

michael_reeves
Engager

You may want to try the BREAK_ONLY_BEFORE_DATE boolian config option outlined in the Splunk Doc found at http://docs.splunk.com/Documentation/Splunk/6.0.3/Data/Indexmulti-lineevents

View solution in original post

0 Karma

michael_reeves
Engager

You may want to try the BREAK_ONLY_BEFORE_DATE boolian config option outlined in the Splunk Doc found at http://docs.splunk.com/Documentation/Splunk/6.0.3/Data/Indexmulti-lineevents

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...