I have a file with multiline events. Though there is no structured data in the events, the events themselves can be identified by proper splits. Below is an example
Frame 1: 110 bytes on wire (880 bits), 110 bytes captured (880 bits)
Arrival Time: Dec 20, 2007 14:01:56.000165000 India Standard Time
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1198139516.000165000 seconds
[Time delta from previous captured frame: 0.000000000 seconds]
[Time delta from previous displayed frame: 0.000000000 seconds]
[Time since reference or first frame: 0.000000000 seconds]
Frame Number: 1
Frame Length: 110 bytes (880 bits)
Capture Length: 110 bytes (880 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:ospf]
Ethernet II, Src: Cisco_f7:97:c2 (00:1b:8f:f7:97:c2), Dst: IPv4mcast_00:00:05 (01:00:5e:00:00:05)
Destination: IPv4mcast_00:00:05 (01:00:5e:00:00:05)
Address: IPv4mcast_00:00:05 (01:00:5e:00:00:05)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast)
Source: Cisco_f7:97:c2 (00:1b:8f:f7:97:c2)
Address: Cisco_f7:97:c2 (00:1b:8f:f7:97:c2)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: (, Dst: (
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0xc0 (DSCP 0x30: Class Selector 6; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
1100 00.. = Differentiated Services Codepoint: Class Selector 6 (0x30)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 96
Identification: 0xd719 (55065)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 1
Protocol: OSPF IGP (89)
Header checksum: 0xdaf5 [correct]
[Good: True]
[Bad: False]
Source: (
Destination: (
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Open Shortest Path First
OSPF Header
OSPF Version: 2
Message Type: Hello Packet (1)
Packet Length: 64
Source OSPF Router: (
Area ID: (Backbone)
Packet Checksum: 0x077d [correct]
Auth Type: Null
Auth Data (none)
OSPF Hello Packet
Network Mask:
Hello Interval: 10 seconds
Options: 0x12 (L, E)
0... .... = DN: DN-bit is NOT set
.0.. .... = O: O-bit is NOT set
..0. .... = DC: Demand Circuits are NOT supported
...1 .... = L: The packet contains LLS data block
.... 0... = NP: NSSA is NOT supported
.... .0.. = MC: NOT Multicast Capable
.... ..1. = E: External Routing Capability
.... ...0 = MT: NO Multi-Topology Routing
Router Priority: 10
Router Dead Interval: 40 seconds
Designated Router:
Backup Designated Router:
Active Neighbor:
Active Neighbor:
Active Neighbor:
Active Neighbor:
Active Neighbor:
OSPF LLS Data Block
Checksum: 0xfff6
LLS Data Length: 12 bytes
Extended options TLV
Type: 1
Length: 4
Options: 0x00000001 (LR)
.... .... .... .... .... .... .... ..0. = RS: Restart Signal (RS-bit) is NOT set
.... .... .... .... .... .... .... ...1 = LR: LSDB Resynchronization (LR-bit) is SET
Frame 2: 110 bytes on wire (880 bits), 110 bytes captured (880 bits)
Arrival Time: Dec 20, 2007 14:01:56.000173000 India Standard Time
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1198139516.000173000 seconds
[Time delta from previous captured frame: 0.000008000 seconds]
[Time delta from previous displayed frame: 0.000008000 seconds]
[Time since reference or first frame: 0.000008000 seconds]
Frame Number: 2
Frame Length: 110 bytes (880 bits)
Capture Length: 110 bytes (880 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:ip:ospf]
Ethernet II, Src: Cisco_f7:97:c2 (00:1b:8f:f7:97:c2), Dst: IPv4mcast_00:00:05 (01:00:5e:00:00:05)
Destination: IPv4mcast_00:00:05 (01:00:5e:00:00:05)
Address: IPv4mcast_00:00:05 (01:00:5e:00:00:05)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast)
Source: Cisco_f7:97:c2 (00:1b:8f:f7:97:c2)
Address: Cisco_f7:97:c2 (00:1b:8f:f7:97:c2)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Type: IP (0x0800)
Internet Protocol Version 4, Src: (, Dst: (
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0xc0 (DSCP 0x30: Class Selector 6; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
1100 00.. = Differentiated Services Codepoint: Class Selector 6 (0x30)
.... ..00 = Explicit Congestion Notification: Not-ECT (Not ECN-Capable Transport) (0x00)
Total Length: 96
Identification: 0xd719 (55065)
Flags: 0x00
0... .... = Reserved bit: Not set
.0.. .... = Don't fragment: Not set
..0. .... = More fragments: Not set
Fragment offset: 0
Time to live: 1
Protocol: OSPF IGP (89)
Header checksum: 0xdaf5 [correct]
[Good: True]
[Bad: False]
Source: (
Destination: (
[Source GeoIP: Unknown]
[Destination GeoIP: Unknown]
Open Shortest Path First
OSPF Header
OSPF Version: 2
Message Type: Hello Packet (1)
Packet Length: 64
Source OSPF Router: (
Area ID: (Backbone)
Packet Checksum: 0x077d [correct]
Auth Type: Null
Auth Data (none)
OSPF Hello Packet
Network Mask:
Hello Interval: 10 seconds
Options: 0x12 (L, E)
0... .... = DN: DN-bit is NOT set
.0.. .... = O: O-bit is NOT set
..0. .... = DC: Demand Circuits are NOT supported
...1 .... = L: The packet contains LLS data block
.... 0... = NP: NSSA is NOT supported
.... .0.. = MC: NOT Multicast Capable
.... ..1. = E: External Routing Capability
.... ...0 = MT: NO Multi-Topology Routing
Router Priority: 10
Router Dead Interval: 40 seconds
Designated Router:
Backup Designated Router:
Active Neighbor:
Active Neighbor:
Active Neighbor:
Active Neighbor:
Active Neighbor:
OSPF LLS Data Block
Checksum: 0xfff6
LLS Data Length: 12 bytes
Extended options TLV
Type: 1
Length: 4
Options: 0x00000001 (LR)
.... .... .... .... .... .... .... ..0. = RS: Restart Signal (RS-bit) is NOT set
.... .... .... .... .... .... .... ...1 = LR: LSDB Resynchronization (LR-bit) is SET
Frame 3: 60 bytes on wire (480 bits), 60 bytes captured (480 bits)
Arrival Time: Dec 20, 2007 14:01:56.474107000 India Standard Time
[Time shift for this packet: 0.000000000 seconds]
Epoch Time: 1198139516.474107000 seconds
[Time delta from previous captured frame: 0.473934000 seconds]
[Time delta from previous displayed frame: 0.473934000 seconds]
[Time since reference or first frame: 0.473942000 seconds]
Frame Number: 3
Frame Length: 60 bytes (480 bits)
Capture Length: 60 bytes (480 bits)
[Frame is marked: False]
[Frame is ignored: False]
[Protocols in frame: eth:llc:stp]
IEEE 802.3 Ethernet
Destination: Spanning-tree-(for-bridges)_00 (01:80:c2:00:00:00)
Address: Spanning-tree-(for-bridges)_00 (01:80:c2:00:00:00)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast)
Source: Cisco_f7:97:8a (00:1b:8f:f7:97:8a)
Address: Cisco_f7:97:8a (00:1b:8f:f7:97:8a)
.... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
.... ...0 .... .... .... .... = IG bit: Individual address (unicast)
Length: 38
Padding: 0000000000000000
Logical-Link Control
DSAP: Spanning Tree BPDU (0x42)
IG Bit: Individual
SSAP: Spanning Tree BPDU (0x42)
CR Bit: Command
Control field: U, func=UI (0x03)
000. 00.. = Command: Unnumbered Information (0x00)
.... ..11 = Frame type: Unnumbered frame (0x03)
Spanning Tree Protocol
Protocol Identifier: Spanning Tree Protocol (0x0000)
Protocol Version Identifier: Spanning Tree (0)
BPDU Type: Configuration (0x00)
BPDU flags: 0x00
0... .... = Topology Change Acknowledgment: No
.... ...0 = Topology Change: No
Root Identifier: 32768 / 10 / 00:1b:8f:f7:97:80
Root Bridge Priority: 32768
Root Bridge System ID Extension: 10
Root Bridge System ID: 00:1b:8f:f7:97:80
Root Path Cost: 0
Bridge Identifier: 32768 / 10 / 00:1b:8f:f7:97:80
Bridge Priority: 32768
Bridge System ID Extension: 10
Bridge System ID: 00:1b:8f:f7:97:80
Port identifier: 0x800a
Message Age: 0
Max Age: 20
Hello Time: 2
Forward Delay: 15
Each event can be separated using the word Frame followed by a incremental number and a colon.
I tried the below regex in the props.conf file
BREAK_ONLY_BEFORE = (?m)Frame ([0-9]+):
After doing the above, the events are not split up properly. The first 1500 events are appearing in a random manner and split at improper positions. But the events after 1500 events are split up properly. Can someone help me in finding what is wrong in the way I would have defined the regex
... View more