I want Splunk to break every time I see Event logged at `*}:`
Event logged at {1492205898958;2}:
ID: com.innovision.ofx.ofxsgml.ncph.Response
Title: Event logged at Fri Apr 14 14:38:18 PDT 2017
Severity: INFO
Timestamp: {1492205898958;2}
Date-Time: Fri Apr 14 14:38:18 PDT 2017
Source: com.innovision.ofx.ofxsgml.ncph.OfxResponse
Transaction-ID: 0A044F3301D3BFED0000015B6E2BF39BD246
Host-Name: XXXXXXX
HTTP result code (so far) is 200.
OFX output response message:
Header version: 100
Content type: OFXSGML
DTD version: 102
Security type: NONE
Character encoding: USASCII
Character set: 1252
Compression type: NONE
Old file UID: NONE
New file UID: NONE
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Event logged at {1492205898958;4}:
ID: 0A044F3301D3BFED0000015B6E2BF39BD28D
Title: System.out
Severity: INFO
Timestamp: {1492205898958;4}
Date-Time: Fri Apr 14 14:38:18 PDT 2017
Host-Name: XXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Event logged at {1492205898974;2}:
ID: 0A044F3301D3BFED0000015B6E2BF39BD28E
Title: System.err
Severity: WARNING
Timestamp: {1492205898974;2}
Date-Time: Fri Apr 14 14:38:18 PDT 2017
Host-Name: XXXXXXXX
AccountsServant - returned error 2000
Event logged at {1492205898974;3}:
ID: com.innovision.nepal.controller.XactOut
Title: Event logged at Fri Apr 14 14:38:18 PDT 2017
Severity: INFO
Timestamp: {1492205898974;3}
Date-Time: Fri Apr 14 14:38:18 PDT 2017
Source: com.innovision.nepal.controller.TransactionServant
Transaction-ID: 0A044F3301D3BFED0000015B6E2BF39BD246
Host-Name: XXXXXXXX
Transaction 0A044F3301D3BFED0000015B6E2BF39BD246 is complete.
Total processing time: 00:00:01.407 (1.407s).
Heap memory used: 135977728 of 518979584 bytes (26%).
here is my props.conf:
LINE_BREAKER = ([\r\n])Event logged at *}:
MAX_EVENTS = 2000
NO_BINARY_CHECK = true
disabled = false
pulldown_type = true
↧