Splunk Search

setting up Line Break in props.conf for compiled year month and date

valeriedls01
Loves-to-Learn Everything

I have a log the needs the props.conf setup but the year month and date is complied into one with no spaces or separators.  How can I regex this in the  line breaker or time format 

this is an example of the log start of each event 
20240507 10:47:38.467 [DEBUG] 12672

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could try like

LINE_BREAKER = ([\n\r]+)\d{8} \d\d:\d\d:
TIME_FORMAT = %Y%m%d %H:%M%:%S.%3Q
TIME_PREFIX = ^

 r. Ismo

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...