<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is linecount 2 when it's clearly 1? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744497#M118305</link>
    <description>In splunk _raw is only one line, but it can contains e.g. \n character.&lt;BR /&gt;You could see it e.g. “table _raw”</description>
    <pubDate>Fri, 18 Apr 2025 16:10:20 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-04-18T16:10:20Z</dc:date>
    <item>
      <title>Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744443#M118296</link>
      <description>&lt;P&gt;For multiple sourcetypes, linecount is 2, while clearly, it should be 1. Has anybody encountered this case?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 16:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744443#M118296</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-04-17T16:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744444#M118297</link>
      <description>&lt;P&gt;Example?&amp;nbsp; Screenshot?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 17:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744444#M118297</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-04-17T17:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744469#M118301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196884"&gt;@danielbb&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you share a sample event and screenshot of this so we try and repeat this issue and/or diagnose?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 11:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744469#M118301</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-18T11:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744491#M118304</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;,&amp;nbsp;I'll get screenshots but, a related question, how do I access the second line of _raw?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 15:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744491#M118304</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-04-18T15:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744497#M118305</link>
      <description>In splunk _raw is only one line, but it can contains e.g. \n character.&lt;BR /&gt;You could see it e.g. “table _raw”</description>
      <pubDate>Fri, 18 Apr 2025 16:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744497#M118305</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-18T16:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744588#M118331</link>
      <description>&lt;P class="lia-align-left"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; I'm running the following -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index = &amp;lt;my_index&amp;gt; linecount=2
| table _raw &lt;/LI-CODE&gt;&lt;P&gt;and everything shows up as one line, I don't see any sign of \n, what do I miss?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also checked with an encoding tool and it doesn't show either the 13 ascii code or the 10 one within these lines.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My biggest confusion is the fact that for this sourcetype I have -&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE=FALSE&lt;/LI-CODE&gt;&lt;P&gt;And therefore, how come, sometimes the events have multiple lines?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 20:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744588#M118331</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-04-21T20:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744691#M118347</link>
      <description>&lt;P&gt;I came across an identical thread at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-calculate-linecount/m-p/85599" target="_blank"&gt;Re: How does Splunk calculate linecount? - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 14:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744691#M118347</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-04-22T14:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744701#M118348</link>
      <description>Hoe you have defined line breaking?</description>
      <pubDate>Tue, 22 Apr 2025 17:05:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744701#M118348</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-22T17:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linecount 2 when it's clearly 1?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744727#M118356</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196884"&gt;@danielbb&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be something like a field extraction happening after the line breaking which is causing this, or something else. Without access to your instance we could do with seeing some sample logs along with a btool output ($SPLUNK_HOME/bin/splunk btool props list &amp;lt;sourceTypeName&amp;gt;) for your event's sourcetype.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thread you posted from 2013 looks like could have been related to the events having a line-break in.&lt;/P&gt;&lt;P&gt;Please let us know if you're able to provide a sample + props output.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 22:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linecount-2-when-it-s-clearly-1/m-p/744727#M118356</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-22T22:04:29Z</dc:date>
    </item>
  </channel>
</rss>

