<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk timing issue when forwarding log file in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236185#M8863</link>
    <description>&lt;P&gt;Does this still apply when the issue only happen sometimes? It is the same file, it just seems that the file get fwd before it is done being written. &lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2015 11:35:46 GMT</pubDate>
    <dc:creator>brent_weaver</dc:creator>
    <dc:date>2015-09-22T11:35:46Z</dc:date>
    <item>
      <title>Splunk timing issue when forwarding log file</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236183#M8861</link>
      <description>&lt;P&gt;I am having an issue with a particular log file where two entries get concatenated into one entry. It is not the data because if I take take the same data and add it via file upload it is fine, meaning all lines are unique. Has anyone else had an issue like this? It seems that it is a timing problem that the host if forwarding the same time the file is being written... Is this perhaps the result of the log file not being locked when written to???&lt;/P&gt;

&lt;P&gt;Any help is appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 12:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236183#M8861</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2015-09-21T12:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timing issue when forwarding log file</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236184#M8862</link>
      <description>&lt;P&gt;You need to set line breaking property in your props.conf&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Admin/propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Admin/propsconf&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;
LINE_BREAKER = &amp;lt;regular expression&amp;gt;
* Specifies a regex that determines how the raw text stream is broken into initial events,
&lt;/PRE&gt;</description>
      <pubDate>Mon, 21 Sep 2015 17:54:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236184#M8862</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2015-09-21T17:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk timing issue when forwarding log file</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236185#M8863</link>
      <description>&lt;P&gt;Does this still apply when the issue only happen sometimes? It is the same file, it just seems that the file get fwd before it is done being written. &lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2015 11:35:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-timing-issue-when-forwarding-log-file/m-p/236185#M8863</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2015-09-22T11:35:46Z</dc:date>
    </item>
  </channel>
</rss>

