Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I configure proper line breaking for my sample multiline event in Splunk 6.4?

$
0
0
Hi... I am using a Mainframe log which has different type of events. I am only trying to split the lines of events which look like below and no other events. How can I configure this using Line_breaker. MR0000000 DCXA 15217 01:00:01.96 INTERNAL 00000090 IEE949I 01.00.01 SMF DATA SETS 929 DR 929 00000090 NAME VOLSER SIZE(BLKS) %FULL STATUS DR 929 00000090 P-SYS1.MAN1 C7SP09 99630 0 ALTERNATE DR 929 00000090 S-SYS1.MAN2 C7SP14 99630 33 ACTIVE DR 929 00000090 S-SYS1.MAN3 C7SP20 99630 0 ALTERNATE DR 929 00000090 S-SYS1.MAN4 C7SP21 99630 0 ALTERNATE DR 929 00000090 S-SYS1.MAN5 C7SP78 100080 0 ALTERNATE DR 929 00000090 S-SYS1.MAN6 C7SP88 100080 0 ALTERNATE ER 929 00000090 S-SYS1.MAN7 C7SP89 100080 0 ALTERNATE

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>