Splunk Search

setting up Line Break in props.conf for compiled year month and date

valeriedls01
Loves-to-Learn Everything

I have a log the needs the props.conf setup but the year month and date is complied into one with no spaces or separators.  How can I regex this in the  line breaker or time format 

this is an example of the log start of each event 
20240507 10:47:38.467 [DEBUG] 12672

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could try like

LINE_BREAKER = ([\n\r]+)\d{8} \d\d:\d\d:
TIME_FORMAT = %Y%m%d %H:%M%:%S.%3Q
TIME_PREFIX = ^

 r. Ismo

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...