Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

props.conf config for line breaking

$
0
0
Hi All, I am having problems splitting lines of a log file. the log entry is below; [DEBUG 2019-09-26 09:15:57:765] Logger Proxy STARTED [DEBUG 2019-09-26 09:15:57:765] Logger Servlet Called (13024624) times [DEBUG 2019-09-26 09:15:57:765] Logger SetResponseDefaults [FATAL 2019-09-26 09:15:57:765] Logger Proxy - Illegal or missing SubscriberId below is my props.conf file entry [jams_log] SHOULD_LINEMERGE = true BREAK_ONLY_BEFORE_DATE = false BREAK_ONLY_BEFORE = \^[\D{5}\s\d{4}\-\d{2}\-\d{2}\s\d{2}:\d{2}:\d{2}\.\d{3}] MAX_TIMESTAMP_LOOKAHEAD = 31 TIME_PREFIX = ^ I thought it was because i did not have TIME_FORMAT, however this did not work either. any help would be much appreciated.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>