Hello,
I have the raw data coming to splunk but lines are not breaking and getting multiple events in 1 event without breaking. I tried to write below props but not working.
Please do help me.
Thanks in advance!
[ ]
BREAK_ONLY_BEFORE=(\")?8
CHARSET=AUTO
SHOULD_LINEMERGE=false
TRUNCATE=0
LINE_BREAKER=([\r\n]+)
EVENT_BREAKER_ENABLE=true
NO_BINARY_CHECK=true
"8;3;03e524cc-2a8e-48de-bb87-b6ea76a0d2ae;00000001-0001-0001-0001-000000033056;""33056: DNS: Samba AD DC Null Pointer Dereference Denial-of-Service Vulnerability"";33056;""dns"";***.***.***.***;1234;***.***.***.***;1234;1;1-2B;1-2A;5;0;""SNSCNESDZ3.cn.sub"";67045373;1571223850056; ;416852147
8;3;03e524cc-2a8e-48de-bb87-b6ea76a0d2ae;00000001-0001-0001-0001-000000033056;""33056: DNS: Samba AD DC Null Pointer Dereference Denial-of-Service Vulnerability"";33056;""dns"";***.***.***.***;1234;***.***.***.***;1234;1;1-2B;1-2A;5;0;""SNSCNESDZ3.cn.sub"";67045373;1571223851059; ;416852148
8;3;03e524cc-2a8e-48de-bb87-b6ea76a0d2ae;00000001-0001-0001-0001-000000033056;""33056: DNS: Samba AD DC Null Pointer Dereference Denial-of-Service Vulnerability"";33056;""dns"";***.***.***.***;1234;***.***.***.***;1234;1;1-2B;1-2A;5;0;""SNSCNESDZ3.cn.sub"";67045373;1571223852016; ;416852149
8;3;03e524cc-2a8e-48de-bb87-b6ea76a0d2ae;00000001-0001-0001-0001-000000033056;""33056: DNS: Samba AD DC Null Pointer Dereference Denial-of-Service Vulnerability"";33056;""dns"";***.***.***.***;1234;***.***.***.***;1234;1;1-2B;1-2A;5;0;""SNSCNESDZ3.cn.sub"";67045373;1571223853046; ;416852150
8;3;03e524cc-2a8e-48de-bb87-b6ea76a0d2ae;00000001-0001-0001-0001-000000033056;""33056: DNS: Samba AD DC Null Pointer Dereference Denial-of-Service Vulnerability"";33056;""dns"";***.***.***.***;1234;***.***.***.***;1234;1;1-2B;1-2A;5;0;""SNSCNESDZ3.cn.sub"";67045373;1571223854073; ;416852151
↧