I have a pretty long log that needs to be analyzed, not single lined though, here is example #1:
.....some unimportant data many lines...
2011-11-07 13:05:48,060 INFO com.mysoftware.log.splunk.test.Processor: loadStatus = NEW
2011-11-07 13:05:47,984 INFO com.mysoftware.log.splunk.test.Processor: DELTA status determined for record with ID: 010bbd25aeccaacb564fab543c5b0429083c804a
2011-11-07 13:05:47,984 INFO com.mysoftware.log.splunk.test.Processor: DELTA status: ID=bebbe8570c4ce87238378b53241a976a5528dfaf, {TEST:DELTA_STATUS=NEW, TEST:JOB_ID=job_201110281559_2009, TEST:LAST_UPDATED_TIMESTAMP=Mon, 7 Nov 2011 13:05:47, TEST:ROW_ID=010bbd25aeccaacb564fab543c5b0429083c804a, TEST:LOAD_JOB_ID=job_201110281559_2008}
2011-11-07 13:05:48,060 INFO com.mysoftware.log.splunk.test.Processor: loadStatus = NEW
2011-11-07 13:05:48,060 INFO com.mysoftware.log.splunk.test.Processor: DELTA status determined for record with ID: 0141daa46fa7a576b538d2437a339f8ad041f0b7
2011-11-07 13:05:48,060 INFO com.mysoftware.log.splunk.test.Processor: DELTA status: ID=ecaf46341bb7c040ece713e87f0308308093838c, {TEST:DELTA_STATUS=NEW, TEST:JOB_ID=job_201110281559_2009, TEST:LAST_UPDATED_TIMESTAMP=Mon, 7 Nov 2011 13:05:48, TEST:ROW_ID=0141daa46fa7a576b538d2437a339f8ad041f0b7, TEST:LOAD_JOB_ID=job_201110281559_2008}
2011-11-07 13:05:48,130 INFO com.mysoftware.log.splunk.test.Processor: loadStatus = NEW
2011-11-07 13:05:48,130 INFO com.mysoftware.log.splunk.test.Processor: DELTA status determined for record with ID: 01b9bba9474f3c838931242883a7462722fb45b1
2011-11-07 13:05:48,130 INFO com.mysoftware.log.splunk.test.Processor: DELTA status: ID=c9711472457d8f4b226c75da5a9ce2cfee099680, {TEST:DELTA_STATUS=NEW, TEST:JOB_ID=job_201110281559_2009, TEST:LAST_UPDATED_TIMESTAMP=Mon, 7 Nov 2011 13:05:48, TEST:ROW_ID=01b9bba9474f3c838931242883a7462722fb45b1, TEST:LOAD_JOB_ID=job_201110281559_2008}
Here is example of how one line/record should look like, example #2:
2011-11-07 13:05:48,060 INFO com.mysoftware.log.splunk.test.Processor: loadStatus = NEW
2011-11-07 13:05:47,984 INFO com.mysoftware.log.splunk.test.Processor: DELTA status determined for record with ID: 010bbd25aeccaacb564fab543c5b0429083c804a
2011-11-07 13:05:47,984 INFO com.mysoftware.log.splunk.test.Processor: DELTA status: ID=bebbe8570c4ce87238378b53241a976a5528dfaf, {TEST:DELTA_STATUS=NEW, TEST:JOB_ID=job_201110281559_2009, TEST:LAST_UPDATED_TIMESTAMP=Mon, 7 Nov 2011 13:05:47, TEST:ROW_ID=010bbd25aeccaacb564fab543c5b0429083c804a, TEST:LOAD_JOB_ID=job_201110281559_2008}
So this example #1 should be read as 3 records(3 lines), not multiple lines as usual. I went trough some splunk documents realized that I need to add a new source type and define line breaking for myself.
And in my etc/system/local added props.conf and inside defined new source type and added } as a LINE_BREAKER but it's not working it seems that it breaks my line by default when it sees the timestamp. How do I do this? How do I make splunk treat these 3 separate lines as one?
... View more