<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk incorrect default line breaking in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633115#M108401</link>
    <description>&lt;P&gt;This props.conf is in my /splunk/etc/apps/search/local and made in my search head (Setting -&amp;gt; Source types -&amp;gt; New Source type). We have a structure of 1 Master (and where we manage deployment apps) 1 search head and 4 indexer cluster. In most case, we create source type directly in our Search head. So you're telling me I should have setup props.conf in my indexer cluster for it to work correctly?&lt;/P&gt;</description>
    <pubDate>Fri, 03 Mar 2023 08:20:45 GMT</pubDate>
    <dc:creator>phamxuantung</dc:creator>
    <dc:date>2023-03-03T08:20:45Z</dc:date>
    <item>
      <title>Splunk incorrect default line breaking- What am I doing wrong?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633098#M108399</link>
      <description>&lt;P&gt;Hello, I have a sourcetype that have a default LINE_BREAKING and SHOULD_LINEMERGE=false, like so:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phamxuantung_0-1677818696153.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24162i0A3F552A794D2206/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phamxuantung_0-1677818696153.png" alt="phamxuantung_0-1677818696153.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Per my understanding, this mean it automatically extract each line as one event. But the indexed data is like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lnie break.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24163i609F1CBF31B20BE5/image-size/large?v=v2&amp;amp;px=999" role="button" title="lnie break.PNG" alt="lnie break.PNG" /&gt;&lt;/span&gt;The red event is correct with linecount=1, but most of the events have linecount=2, some have event more without line breaking. So what should I fix?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 18:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633098#M108399</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2023-03-03T18:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk incorrect default line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633110#M108400</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;where did you located this props.conf?&lt;/P&gt;&lt;P&gt;it must be located on Indexers and (if present) on intermediate Heavy Forwarders, not on Universal Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 07:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633110#M108400</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-03T07:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk incorrect default line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633115#M108401</link>
      <description>&lt;P&gt;This props.conf is in my /splunk/etc/apps/search/local and made in my search head (Setting -&amp;gt; Source types -&amp;gt; New Source type). We have a structure of 1 Master (and where we manage deployment apps) 1 search head and 4 indexer cluster. In most case, we create source type directly in our Search head. So you're telling me I should have setup props.conf in my indexer cluster for it to work correctly?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 08:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633115#M108401</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2023-03-03T08:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk incorrect default line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633124#M108404</link>
      <description>&lt;P&gt;I setup for sourcetype in props.conf in my indexer with&lt;/P&gt;&lt;P&gt;LINE_BREAKER = ([\r\n]+)&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;But it still indexed with incorrect line break&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 09:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633124#M108404</guid>
      <dc:creator>phamxuantung</dc:creator>
      <dc:date>2023-03-03T09:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk incorrect default line breaking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633125#M108405</link>
      <description>&lt;P&gt;&lt;SPAN&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230393"&gt;@phamxuantung&lt;/a&gt;&amp;nbsp;LINE_BREAKER is applied during the Parsing Pipeline, so the instance with the&amp;nbsp;LINE_BREAKER and&amp;nbsp;SHOULD_LINEMERGE = false (merging pipeline) must be set on HF/Indexer level.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;LINE_BREAKER on Search Heads would work if that Search Heads are directly indexing events (i.e. in Splunk all-in-one architectures), hence parsing events themself.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Fabrizio&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 10:33:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-incorrect-default-line-breaking-What-am-I-doing-wrong/m-p/633125#M108405</guid>
      <dc:creator>LRF</dc:creator>
      <dc:date>2023-03-03T10:33:29Z</dc:date>
    </item>
  </channel>
</rss>

