Hello, I have a log file where each event starts with a date, however, there are two date formats. There are multi lines in some of the events and some of the data are separated by a blank line. Upon uploading the file, Splunk thinks the blank line is the start of a new event, so for every line after that blank line, it splits the data into a new event. Here's an example: 2020-11-02 18:40:31,293+0000 some data INFO some more data 2020-11-03 18:40:31,293+0000 some data INFO some more data 2020-11-05 18:40:31,293+0000 some data INFO some more data 06-FEB-2020 18:40:11.289 INFO [main} data some more data 2020-11-12 18:40:31,293+0000 some data INFO some more data data to look for ___testing________ ID:0 type: Fruit Name: Mango Desc: Ripe 2020-11-22 18:40:31,293+0000 some data INFO some more data starting something new 2020-11-23 18:40:31,293+0000 some data INFO some more data I think by telling splunk to ignore blank lines or remove it, should fix my problem as I want to keep all multiline data together within the event that starts with a date, but I haven't had much luck with getting the appropriate regex to work. I hope the experts can help with this. Thanks in advance.
... View more