<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index Line Breaks in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48809#M22158</link>
    <description>&lt;P&gt;I know, I had a co-worker of mine who's more knowledgeable than I take a look and he was confused as well.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2013 18:48:37 GMT</pubDate>
    <dc:creator>Daniel_Edwards</dc:creator>
    <dc:date>2013-03-01T18:48:37Z</dc:date>
    <item>
      <title>Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48807#M22156</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm getting input from a log file the contents of which are a long listing a directory containing .rpm files.  When I search on the source or sourcetype I get a singe event for every line in the log file.  When I search on the index I directed the input to go to, it lumps entries together:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-rw------- 1 root root 1.2M Sep  3 13:17 cyrus-sasl-2.1.22-7.el5_8.1.x86_64.rpm
-rw------- 1 root root 127K Sep  3 13:15 cyrus-sasl-lib-2.1.22-7.el5_8.1.i386.rpm
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is one event instead of two.&lt;/P&gt;

&lt;P&gt;props.conf looks like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[sourcetype::RHEL_mon_log]&lt;BR /&gt;
MUST_BREAK_AFTER = &amp;lt;\Q.rpm\E&amp;gt;&lt;BR /&gt;
SHOULD_LINEMERGE=true&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2013 17:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48807#M22156</guid>
      <dc:creator>Daniel_Edwards</dc:creator>
      <dc:date>2013-03-01T17:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48808#M22157</link>
      <description>&lt;P&gt;I don't really get it - you're directing these logs to a particular index, and you get different results if you do "index=theindex" than if you do "sourcetype=thesourcetype"?? That sounds very weird to me...&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2013 18:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48808#M22157</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-01T18:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48809#M22158</link>
      <description>&lt;P&gt;I know, I had a co-worker of mine who's more knowledgeable than I take a look and he was confused as well.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2013 18:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48809#M22158</guid>
      <dc:creator>Daniel_Edwards</dc:creator>
      <dc:date>2013-03-01T18:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48810#M22159</link>
      <description>&lt;P&gt;I can see that, because there's no reason why it would act like that. Could you please post more details about your searches?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2013 19:10:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48810#M22159</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-01T19:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48811#M22160</link>
      <description>&lt;P&gt;The search I'm using is "index=rhel_update_mon". I'm relatively new to splunk so I'm trying to do the KISS thing and move on once I have a good understanding of the basics.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48811#M22160</guid>
      <dc:creator>Daniel_Edwards</dc:creator>
      <dc:date>2020-09-28T13:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48812#M22161</link>
      <description>&lt;P&gt;OK, and the other search, for source/sourcetype?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2013 19:45:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48812#M22161</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-01T19:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48813#M22162</link>
      <description>&lt;P&gt;I think you have have helped me solve the problem!  I believe the sourcetype I had in my props.conf was incorrect.  It needed to be [rhel_update_log] and not [RHEL_mon_log] Thank you very much.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48813#M22162</guid>
      <dc:creator>Daniel_Edwards</dc:creator>
      <dc:date>2020-09-28T13:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Index Line Breaks</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48814#M22163</link>
      <description>&lt;P&gt;Via Ayn:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  Confirm that the sourcetype in your props.conf matches what sourcetype is actually in splunk.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 01 Mar 2013 20:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Line-Breaks/m-p/48814#M22163</guid>
      <dc:creator>Daniel_Edwards</dc:creator>
      <dc:date>2013-03-01T20:02:23Z</dc:date>
    </item>
  </channel>
</rss>

