<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WARN  LineBreakingProcessor in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576277#M101829</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Nov 2021 02:06:09 GMT</pubDate>
    <dc:creator>jadengoho</dc:creator>
    <dc:date>2021-11-25T02:06:09Z</dc:date>
    <item>
      <title>WARN  LineBreakingProcessor</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576138#M101812</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;BR /&gt;I have a log with 3 event inside of it, (&amp;nbsp;&lt;EM&gt;you can see it on the screenshot,&amp;nbsp;I paste the sample logs here :&amp;nbsp;&lt;A href="https://regex101.com/r/EvmMeR/1" target="_blank"&gt;https://regex101.com/r/EvmMeR/1&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1st Event -&amp;nbsp; Short event&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;2nd Event - Short event and multi-line&lt;/LI&gt;&lt;LI&gt;3rd Event - VERY LONG and multi-line, need to be dropped as per the client.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jadengoho_0-1637740603378.png" style="width: 1257px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16990i47B8B1017D7502C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jadengoho_0-1637740603378.png" alt="jadengoho_0-1637740603378.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I manage to DROP the 3rd event by finding the LOGS that are greater than 2000 characters.&lt;/P&gt;&lt;P&gt;The problem is , I dropped the event but Splunk still raise the issue:&lt;BR /&gt;&lt;SPAN class=""&gt;11-24-2021&lt;/SPAN&gt; &lt;SPAN class=""&gt;08:02:57.049&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0000&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;WARN&lt;/SPAN&gt; &lt;SPAN class=""&gt;LineBreakingProcessor&lt;/SPAN&gt; [&lt;SPAN class=""&gt;6453&lt;/SPAN&gt; &lt;SPAN class=""&gt;parsing&lt;/SPAN&gt;] &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Truncating&lt;/SPAN&gt; &lt;SPAN class=""&gt;line&lt;/SPAN&gt; &lt;SPAN class=""&gt;because&lt;/SPAN&gt; &lt;SPAN class=""&gt;limit&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;2000&lt;/SPAN&gt; &lt;SPAN class=""&gt;bytes&lt;/SPAN&gt; &lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;been&lt;/SPAN&gt; &lt;SPAN class=""&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;line&lt;/SPAN&gt; &lt;SPAN class=""&gt;length&lt;/SPAN&gt; &amp;gt;&lt;SPAN class=""&gt;=&lt;/SPAN&gt; &lt;SPAN class=""&gt;55179&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;data_source=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;SAMPLETOSHARE.txt&lt;/SPAN&gt;", &lt;SPAN class=""&gt;data_host=&lt;/SPAN&gt;"&lt;SPAN class=""&gt;5bfd55dbdcdd&lt;/SPAN&gt;", &lt;SPAN class=""&gt;data_sourcetype=&lt;/SPAN&gt;"sample&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jadengoho_1-1637740993087.png" style="width: 1882px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16991i8267701040E10E6D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jadengoho_1-1637740993087.png" alt="jadengoho_1-1637740993087.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to stop splunk from flagging issue for those logs that&amp;nbsp; was dropped ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 08:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576138#M101812</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2021-11-24T08:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: WARN  LineBreakingProcessor</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576187#M101822</link>
      <description>&lt;P&gt;Line breaking happens before any transforms that might discard events so the log message has already been written by the time the event is dropped.&amp;nbsp; There's no way to avoid that, except by using a third-party tool like Cribl to discard events before they reach the indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 14:08:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576187#M101822</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-24T14:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: WARN  LineBreakingProcessor</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576277#M101829</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 02:06:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WARN-LineBreakingProcessor/m-p/576277#M101829</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2021-11-25T02:06:09Z</dc:date>
    </item>
  </channel>
</rss>

