957978 11:23:33 (INTEL) IN: "IFBFE4F44" user@hostlx8.domain $
957979 11:24:07 (MLM) IN: "MATLAB" user@hostlx1.domain $
957980 11:24:07 (MLM) IN: "Statistics_Toolbox" user@hostx1.domain $
957981 11:24:17 (MLM) DENIED: "MATLAB" user@hostx1.domain (User/host on EXCLUDE list for feature. (-38,348))$
957982 11:24:17 (MLM) OUT: "MATLAB" user@hostx1.domain $
957983 11:27:05 (MLM) DENIED: "Statistics_Toolbox" user@hostx1.domain (User/host on EXCLUDE list for feature. (-38,348))$
957984 11:27:05 (MLM) OUT: "Statistics_Toolbox" user@hostx1.domain $
957985 11:27:14 (INTEL) OUT: "IFBFE4F44" user@hostlx36.domain $
957986 11:27:14 (INTEL) OUT: "FCompL" user@hostlx36.domain $
957987 11:27:14 (INTEL) IN: "FCompL" user@hostlx36.domain $
957988 11:27:14 (INTEL) IN: "IFBFE4F44" user@hostlx36.domain $
Using the list mode of vim to display hidden characters hence the $.
:set list
/splunk/etc/system/local/props.conf
[license-logs]
SHOULD_LINEMERGE = false
LINE_BREAKER = (\n)
(We also tried, (\s*\n) )
Results in events in splunk being indexed as:
957978 11:23:33 (INTEL) IN: "IFBFE4F44" user@hostlx8.domain $
957979 11:24:07 (MLM) IN: "MATLAB" user@hostlx1.domain $
957980 11:24:07 (MLM) IN: "Statistics_Toolbox" user@hostx1.domain $
957981 11:24:17 (MLM) DENIED: "MATLAB" user@hostx1.domain (User/host on EXCLUDE list for feature. (-38,348))$
957982 11:24:17 (MLM) OUT: "MATLAB" user@hostx1.domain $
957983 11:27:05 (MLM) DENIED: "Statistics_Toolbox" user@hostx1.domain (User/host on EXCLUDE list for feature. (-38,348))$
957984 11:27:05 (MLM) OUT: "Statistics_Toolbox" user@hostx1.domain $
957985 11:27:14 (INTEL) OUT: "IFBFE4F44" user@hostlx36.domain $
957986 11:27:14 (INTEL) OUT: "FCompL" user@hostlx36.domain $
957987 11:27:14 (INTEL) IN: "FCompL" user@hostlx36.domain $
957988 11:27:14 (INTEL) IN: "IFBFE4F44" user@hostlx36.domain $
EDIT:The events are being grouped on timestamp. I want each line to always be its own event.
EDIT2: As suggested I put LINE_BREAKER = ([\r\n]+) this still didn't put each line in its own event. Splunk was restarted
... View more