Symptom
In the Event Breaker Ruleset rule editor, the Out tab renders an empty table for pasted or uploaded sample data. No events, no error, and no warning appear, so the rule looks broken even though it breaks events correctly on live data.
The behavior occurs when the rule's Filter condition references a metadata field rather than _raw. For example:
sourcetype == 'postgresql:uf'
__collectible.collectorId == 'my_collector_id'
Setting the Filter condition to true makes the expected broken events appear immediately in the Out tab.
Environment
- Cribl Stream 4.19.2
- Cribl.Cloud and self-managed.
- Component: Processing > Knowledge > Event Breaker Rulesets rule editor preview.
- Affects all Event Breaker types, including Regex and JSON Array.
Resolution
The Event Breaker itself is working. This is a preview limitation, not a rule defect. Verify the breaker logic with a temporary filter, then restore the original expression.
- Open Processing > Knowledge > Event Breaker Rulesets and select the ruleset containing the affected rule.
- Note the current Filter condition expression verbatim so you can restore it exactly.
- Set the Filter condition to
true. - Select the Out tab and confirm the sample data breaks into the expected events, and that the extracted timestamp in the leftmost column is correct.
- Restore the original Filter condition from step 2.
- Click OK, then save and deploy the ruleset.
- Verify the rule against live data: start a capture on the Source that uses this ruleset and confirm events arrive correctly broken.
Note: Step 5 is mandatory. Leaving the Filter condition set to true makes the rule match every incoming stream on that Source, which causes it to win over all later rules and rulesets. The first matching rule always wins, and no others are evaluated.
Confirming the rule works on live data
Because the preview cannot evaluate metadata, live capture is the only reliable verification for a metadata-filtered rule.
- Open the Source that references the ruleset.
- Start a live capture with a filter matching the relevant traffic.
- Confirm event boundaries and
_timevalues in the captured events.
Preventive measures
- Where possible, write Event Breaker rule filters against
_rawcontent so the rule is testable in the preview pane. - Keep the sample data in the preview pane at roughly 500 KB or less. The limit is a browser constraint and does not apply to live processing.
- Metadata added under a Source's Fields section is applied after event breaking, so it is never available to an Event Breaker filter. Filter on fields the Source itself sets, such as
__inputIdor__collectible.*.
Cause
The Event Breaker rule preview builds a synthetic event from the sample text that contains only three fields: _raw, __channel set to preview, and __FIN set to true. It does not populate metadata such as sourcetype, index, host, or __collectible.*, because that metadata is supplied by the Source or Collector at ingest time and no Source is involved in the preview.
The preview then evaluates the rule's Filter condition against this synthetic event and only breaks events when the condition returns a truthy value. An expression referencing a field that does not exist evaluates to undefined, which coerces to false. The preview therefore returns an empty event array and renders an empty Out table with no explanation.
On live data the metadata is present, the condition evaluates normally, and the breaker applies as configured. The gap is confined to the preview pane.
Additional Information
See Event Breakers for general event-breaking guidance.
