Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to edit props.conf for proper line breaking of a log file that does not have YYYY-MM-DD in the timestamp?

$
0
0
Events are not breaking up correctly for this particular log file that does not have `YYYY-MM-DD` in the timestamp. Here is the log from one of the apsp that was not so greatly written. I say this because the log does not have `YYYY-MM-DD` as part of the timestamp. Log file: 16:35:34,985 INFO 604682869 [ FailureHandlerBean] Scena startTime=Wed Oct 19 16:35:25 EST 2016] 16:35:34,988 INFO 604682869 [ LockHandler] Invalidated lock Tool. 16:35:34,998 INFO 604682869 [ PFMInterceptor] Executed in Engine 9313ms 16:35:35,002 INFO 604681893 [ JmsQueueMonitor] Current message count in EventQueue: 34 props.conf [server_log] NO_BINARY_CHECK = 1 SHOULD_LINEMERGE = false LINE_BREAKER = ([\r\n]+)\d{2}:\d{2}:\d{2},\d{3} pulldown_type = 1 Any idea? Thanks in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>