Hello Splunk Community, Just starting out configuring Splunk and having an issue with my Time Stamps and line Breaks. Currently Events in the log are using one time stamp seen below in the top left (red). I want to separate all the events that have all their unique MXT time events (green). I tried setting sourcetypes to Auto but also believe I need to fix my line breaks and not sure how/where to configure this. Any help is appreciated, thank you. Example: 10/22/20 3:45:04.000 AM ... 24 lines omitted ... BLANKUSER 10/16/20 03:10:13 MXT CMND TSS ADD(XFERER) SUS BLANKUSER 10/16/20 03:10:13 MXT CMND TSS ADD(XFDGWR) SUS BLANKUSER 10/16/20 07:00:07 MXT CMND TSS CRE(DFETET) NAME('DOE, JOHN') TYPE(USER) DEPT(SA81195) PASS( ,60,EXP) PROFILE(PRO ADTCS) BLANKUSER 10/16/20 07:00:08 MXT CMND TSS ADD(EREFETE) DSNAME(DRERER.)
... View more