<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk File Monitoring Line Breaking not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708659#M117072</link>
    <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884" target="_blank"&gt;@PickleRick&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp; Thank you for the replies!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think I should provide more information about the log. It is from snmp traps, and I have a script that will export the trap line by line to the log file that will be monitored by Splunk.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The props.conf &lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884" target="_blank"&gt;@PickleRick&lt;/A&gt;&amp;nbsp; helped to amend works well if I use 'add data' to add a static log file instead of file monitoring, but If I use file monitoring (new lines of snmp traps will be written around every 10 minutes), the line breaking went wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So I was thinking is the problem due to the file being updated? But the snmp traps were written almost at the same time (as seen in the timestamps), if I would like to fix it, what configurations can I change?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2025 01:05:16 GMT</pubDate>
    <dc:creator>ariel_esh</dc:creator>
    <dc:date>2025-01-14T01:05:16Z</dc:date>
    <item>
      <title>Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708567#M117044</link>
      <description>&lt;P&gt;Hello, I was trying to ingest snmptrapd logs with self file monitoring (Only one Splunk Instance in my environment)&lt;/P&gt;&lt;P&gt;Here is the log format:&lt;/P&gt;&lt;P&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 10:55:44&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:17:26:51.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osDiskFreeSpaceNotification&lt;BR /&gt;CYBER-ARK-MIB::osDiskDrive "C:\\"&lt;BR /&gt;CYBER-ARK-MIB::osDiskPercentageFreeSpace "71.61"&lt;BR /&gt;CYBER-ARK-MIB::osDiskFreeSpace "58221"&lt;BR /&gt;CYBER-ARK-MIB::osDiskTrapState "Alert"&lt;BR /&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 10:55:44&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:17:26:51.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osMemoryUsageNotification&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbPhysical 16776172&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbPhysical 13524732&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbSwap 19266540&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbSwap 3660968&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTrapState "Alert"&lt;BR /&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 10:55:44&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:17:26:51.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osSwapMemoryUsageNotification&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbPhysical 16776172&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbPhysical 13524732&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbSwap 19266540&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbSwap 3660968&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTrapState "Alert"&lt;/P&gt;&lt;P&gt;I tried to use "&amp;lt;UNKNOWN&amp;gt;" as the line breaker, but it does not work at all and the event is broke in a weird way(sometimes it works, most of the time it doesn't)&lt;/P&gt;&lt;P&gt;Please find the props.conf setting as below:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[cyberark:snmplogs]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;LINE_BREAKER&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;\&amp;lt;UNKNOWN\&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NO_BINARY_CHECK&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SHOULD_LINEMERGE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;category&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Custom&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;pulldown_type&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;BREAK_ONLY_BEFORE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;\&amp;lt;UNKNOWN\&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;MUST_NOT_BREAK_BEFORE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;\&amp;lt;UNKNOWN\&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;disabled&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;LINE_BREAKER_LOOKBEHIND&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;2000&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Line Breaking Result in Splunk:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrome_gaC6vhffRn.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34115i41C3895B8F4CC6B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="chrome_gaC6vhffRn.png" alt="chrome_gaC6vhffRn.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Jan 2025 03:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708567#M117044</guid>
      <dc:creator>ariel_esh</dc:creator>
      <dc:date>2025-01-13T03:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708575#M117048</link>
      <description>&lt;P&gt;Don't use SHOULD_LINEMERGE=true. It's a very very rarely useful option.&lt;/P&gt;&lt;P&gt;In your case it will be probably just&lt;/P&gt;&lt;P&gt;LINE_BREAKER=([\r\n]+)&amp;lt;UNKNOWN&amp;gt;&lt;/P&gt;&lt;P&gt;You might need to escape &amp;lt; and &amp;gt; and maybe enclose &amp;lt;UNKNOWN&amp;gt; in a non-capturing group.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 07:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708575#M117048</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-01-13T07:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708580#M117050</link>
      <description>&lt;P&gt;Thank you for the reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have changed the props.conf to&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[cyberark:snmplogs]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;LINE_BREAKER&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;([\r\n]+)\&amp;lt;UNKNOWN\&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NO_BINARY_CHECK&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;category&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Custom&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;pulldown_type&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;disabled&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;false&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;However, the line breaking is still wrong. Sometimes, Splunk even only ingest the first line for that event (16:04:48). Do you have any idea on the reason behind this?&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ariel_esh_1-1736755998584.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34117i96E5367D217F62D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ariel_esh_1-1736755998584.png" alt="ariel_esh_1-1736755998584.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actual log file:&lt;/P&gt;&lt;P&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 16:04:48&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:22:35:56.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osDRServiceNameNotification&lt;BR /&gt;CYBER-ARK-MIB::osServiceName "CyberArk Vault Disaster Recovery"&lt;BR /&gt;CYBER-ARK-MIB::osServiceStatus "Stopped"&lt;BR /&gt;CYBER-ARK-MIB::osServiceTrapState "Alert"&lt;BR /&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 16:06:17&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:22:37:25.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osDiskFreeSpaceNotification&lt;BR /&gt;CYBER-ARK-MIB::osDiskDrive "C:\\"&lt;BR /&gt;CYBER-ARK-MIB::osDiskPercentageFreeSpace "71.56"&lt;BR /&gt;CYBER-ARK-MIB::osDiskFreeSpace "58183"&lt;BR /&gt;CYBER-ARK-MIB::osDiskTrapState "Alert"&lt;BR /&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 16:06:17&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:22:37:25.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osSwapMemoryUsageNotification&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbPhysical 16776172&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbPhysical 13521168&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbSwap 19266540&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbSwap 3651932&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTrapState "Alert"&lt;BR /&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 16:06:18&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:22:37:25.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osCpuUsageNotification&lt;BR /&gt;CYBER-ARK-MIB::osCpuUsage "0.000000"&lt;BR /&gt;CYBER-ARK-MIB::osCpuTrapState "Alert"&lt;BR /&gt;&amp;lt;UNKNOWN&amp;gt; - 2025-01-13 16:06:18&lt;BR /&gt;UDP: [10.0.216.39]:53916-&amp;gt;[10.0.214.14]:162&lt;BR /&gt;SNMPv2-SMI::mib-2.1.3.0 30:22:37:25.00&lt;BR /&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0 CYBER-ARK-MIB::osMemoryUsageNotification&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbPhysical 16776172&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbPhysical 13521168&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTotalKbSwap 19266540&lt;BR /&gt;CYBER-ARK-MIB::osMemoryAvailKbSwap 3651932&lt;BR /&gt;CYBER-ARK-MIB::osMemoryTrapState "Alert"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 08:13:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708580#M117050</guid>
      <dc:creator>ariel_esh</dc:creator>
      <dc:date>2025-01-13T08:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708583#M117051</link>
      <description>&lt;PRE&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;LINE_BREAKER=([\r\n]+)&amp;lt;UNKNOWN&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;This should do the trick. Of course you need to set your timestamp recognition as well but that's another story.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 08:39:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708583#M117051</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-01-13T08:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708584#M117052</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Based on your sample data and if your props.conf is just what you have shown to us this should be work as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;told.&lt;/P&gt;&lt;P&gt;Quite probably you have something else for those event in your input file. Can you found those problematic events and one before and after from it? Then add those inside editors &amp;lt;/&amp;gt; -block, so we can be sure that there haven't been any editor changes when you are posting those into this thread.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 08:40:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708584#M117052</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-13T08:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708648#M117068</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/272939"&gt;@ariel_esh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1736791175614.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34123iC1B41FB4A4FF59E3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1736791175614.png" alt="kiran_panchavat_0-1736791175614.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 17:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708648#M117068</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-13T17:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708659#M117072</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884" target="_blank"&gt;@PickleRick&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp; Thank you for the replies!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think I should provide more information about the log. It is from snmp traps, and I have a script that will export the trap line by line to the log file that will be monitored by Splunk.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The props.conf &lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884" target="_blank"&gt;@PickleRick&lt;/A&gt;&amp;nbsp; helped to amend works well if I use 'add data' to add a static log file instead of file monitoring, but If I use file monitoring (new lines of snmp traps will be written around every 10 minutes), the line breaking went wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So I was thinking is the problem due to the file being updated? But the snmp traps were written almost at the same time (as seen in the timestamps), if I would like to fix it, what configurations can I change?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 01:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708659#M117072</guid>
      <dc:creator>ariel_esh</dc:creator>
      <dc:date>2025-01-14T01:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708718#M117075</link>
      <description>&lt;P&gt;Do you mean that separate lines are written with 10 minute intervals or every 10 minutes a whole multiline event is written? Anyway, if it's a UF it might help to add EVENT_BREAKER_ENABLE=true and set EVENT_BREAKER to the same value as LINE_BREAKER.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 08:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708718#M117075</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-01-14T08:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk File Monitoring Line Breaking not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708723#M117078</link>
      <description>&lt;P&gt;I set the following in inputs.conf and seems it is working fine now.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;multiline_event_extra_waittime = true
time_before_close = 120&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;I will monitor it for a while and see if the successful event breaking is stable. Thank you for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 15:08:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-File-Monitoring-Line-Breaking-not-working/m-p/708723#M117078</guid>
      <dc:creator>ariel_esh</dc:creator>
      <dc:date>2025-01-14T15:08:56Z</dc:date>
    </item>
  </channel>
</rss>

