<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splitting logs sent over the network in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97282#M20280</link>
    <description>&lt;P&gt;I'm experiencing an issue where logging to splunk over the network (either via TCP or UDP) sometimes chunks multiple lines into the same log entry. Is there any way to force these entries to be split as splunk receives them from the port?&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2010 23:43:53 GMT</pubDate>
    <dc:creator>rwallace</dc:creator>
    <dc:date>2010-12-01T23:43:53Z</dc:date>
    <item>
      <title>Splitting logs sent over the network</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97282#M20280</link>
      <description>&lt;P&gt;I'm experiencing an issue where logging to splunk over the network (either via TCP or UDP) sometimes chunks multiple lines into the same log entry. Is there any way to force these entries to be split as splunk receives them from the port?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2010 23:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97282#M20280</guid>
      <dc:creator>rwallace</dc:creator>
      <dc:date>2010-12-01T23:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splitting logs sent over the network</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97283#M20281</link>
      <description>&lt;P&gt;You probably want to use LINE_BREAKER in your props.conf. See the following link for a detailed description: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Indexmulti-lineevents" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Indexmulti-lineevents&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this isn't particularly helpful, could you describe the data in more detail? If you could provide a sample of what your seeing, that might be useful in clarifying the situation. &lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2010 01:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97283#M20281</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2010-12-02T01:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splitting logs sent over the network</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97284#M20282</link>
      <description>&lt;P&gt;Thanks for the link! It looks like setting SHOULD_LINEMERGE to false fixed the problem.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Dec 2010 02:30:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splitting-logs-sent-over-the-network/m-p/97284#M20282</guid>
      <dc:creator>rwallace</dc:creator>
      <dc:date>2010-12-04T02:30:48Z</dc:date>
    </item>
  </channel>
</rss>

