CrowdStrike Logs Multiline Json Not Working Properly #20944
-
A note for the community
ProblemHi Team, Configuration
Versionvector 0.39.0 (x86_64-unknown-linux-gnu 73da9bb 2024-06-17 16:00:23.791735272) Debug Output
Example Data{ Additional ContextNo response ReferencesNo response |
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 7 replies
-
Hi @navein-kumar , The issue here is that your pattern to end the multi-line grouping Otherwise, you could try a pattern like |
Beta Was this translation helpful? Give feedback.
-
Thanks for quick response.
And is there any remap options to find and merge multi-line JSON into sing-line JSON format. |
Beta Was this translation helpful? Give feedback.
-
I have tried the above config and facing regex error " error: unclosed counted repetition" |
Beta Was this translation helpful? Give feedback.
-
I tested this config and it takes as new line, pls refer screenshot |
Beta Was this translation helpful? Give feedback.
Thanks for quick response.
And is there any remap options to find and merge multi-line JSON into sing-line JSON format.