Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

regex help for props.conf BREAK_ONLY_BEFORE option

$
0
0

So we have a script that runs tests to monitor if a system has changed and the output examples below are the lines I need to break before. This will allow us to easily display the results of the tests. None of the lines of data that include the results have the # preceding them, but they may have a # in the line somewhere. I am hoping someone might suggest a regex that will allow me to break the event appropriately.

BREAK_ONLY_BEFORE=Regex

Jan 17 15:07:58 hostname.test.com filename.pl # check USB access
Jan 17 15:07:58 hostname.test.com filename.pl # check File name access access Jan 17 15:07:58 hostname.test.com filename.pl ##### filename.pl #####
Jan 17 15:07:58 hostname.test.com filename.pl ##### filename1.pl #####

Thanks for any thoughts.


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>