<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why splunk logging truncates rather than wrapping to multiline? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128306#M26341</link>
    <description>&lt;P&gt;Send an example of the data (not too many lines, but representative data) and the contents of the props.conf file for this sourcetype.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Nov 2014 20:25:11 GMT</pubDate>
    <dc:creator>cpetterborg</dc:creator>
    <dc:date>2014-11-20T20:25:11Z</dc:date>
    <item>
      <title>Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128305#M26340</link>
      <description>&lt;P&gt;I'm having issues getting this to work. I have played around with the props.conf but can't seem to get this going.  pass an argument to props.conf  truncate=0 .&lt;/P&gt;

&lt;P&gt;Have tried several configuration attempts. Latest one is to change linemerge = false to linemerge = true . &lt;/P&gt;

&lt;P&gt;After trying these it still chops off the event. Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 17:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128305#M26340</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2014-11-20T17:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128306#M26341</link>
      <description>&lt;P&gt;Send an example of the data (not too many lines, but representative data) and the contents of the props.conf file for this sourcetype.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 20:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128306#M26341</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2014-11-20T20:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128307#M26342</link>
      <description>&lt;P&gt;broker-p3.vsp.com app=BrokerApp [2014-10-20 13:38:14,143] INFO {abcpnhFLDq4THhWxDqVKu} LogInterceptor.before: Invoking appointment-complete&lt;BR /&gt;
broker-p3.vsp.com app=BrokerApp [2014-10-20 13:38:14,149] INFO {abcpnhFLDq4THhWxDqVKu}AppointmentCompleteAction.execute: Broker Registration Info:com.vsp.broker.model.AppointmentFormInfo@61bf56bd[licenses={0=com.vsp.broker.model.BrokerLicense@439a95a[state=MS,licenseNum=10265706,effectiveDate=com.vsp.portal.util.Chrono@659d55e0[day=1,month=10,year=2012,value=,format=MMMM|dd#yyyy]],1=com.vsp.broker.model.BrokerLicense@384bc948[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@778bb2d7[day=,month=,year=,value=,format=MMMM|dd#yyyy]],2=com.vsp.broker.model.BrokerLicense@824cf37[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@28a0280e[day=,month=,year=,value=,format=MMMM|dd#yyyy]],3=com.vsp.broker.model.BrokerLicense@3caf42c7[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@164935f1[day=,month=,year=,value=,fo...&lt;BR /&gt;
broker-p3.vsp.com app=BrokerApp [2014-10-20 13:38:14,317] INFO {abcpnhFLDq4THhWxDqVKu} MailBlock.doAfterBody: Sending 'VSP Resource Center Registration' to &lt;A href="mailto:jennleebush@aol.com"&gt;jennleebush@aol.com&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;that's the sample of data.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 20:51:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128307#M26342</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2014-11-20T20:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128308#M26343</link>
      <description>&lt;P&gt;From this data you have three events, each of which is one line.&lt;/P&gt;

&lt;P&gt;Are you seeing the second line itself truncated to be shorter?&lt;/P&gt;

&lt;P&gt;Do you want to have a multi-line event, or do you want to have one line split into more than one event?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 20:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128308#M26343</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2014-11-20T20:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128309#M26344</link>
      <description>&lt;P&gt;broker-p3.vsp.com app=BrokerApp [2014-10-20 13:38:14,149] INFO  {abcpnhFLDq4THhWxDqVKu} AppointmentCompleteAction.execute: Broker Registration Info: LOG STARTINGcom.vsp.broker.model.AppointmentFormInfo@61bf56bd[licenses={0=com.vsp.broker.model.BrokerLicense@439a95a[state=MS,licenseNum=10265706,effectiveDate=com.vsp.portal.util.Chrono@659d55e0[day=1,month=10,year=2012,value=,format=MMMM|dd#yyyy]], 1=com.vsp.broker.model.BrokerLicense@384bc948[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@778bb2d7[day=,month=,year=,value=,format=MMMM|dd#yyyy]], 2=com.vsp.broker.model.BrokerLicense@824cf37[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@28a0280e[day=,month=,year=,value=,format=MMMM|dd#yyyy]], 3=com.vsp.broker.model.BrokerLicense@3caf42c7[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@164935f1[day=,month=,year=,value=,fo... &lt;STRONG&gt;LINE ENDING and NEXT LINE TRUNCATED&lt;/STRONG&gt;&lt;BR /&gt;
I don't want this truncated. I want a continuation of this event. Does that make sense?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 21:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128309#M26344</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2014-11-20T21:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128310#M26345</link>
      <description>&lt;P&gt;-sh-4.1$ sudo more props.conf&lt;BR /&gt;
[datapower]&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
pulldown_type = 1&lt;/P&gt;

&lt;P&gt;[PMIServlet]&lt;BR /&gt;
NO_BINARY_CHECK = 1&lt;BR /&gt;
pulldown_type = 1&lt;/P&gt;

&lt;P&gt;[host::SCHQVVCACDEM1*]&lt;BR /&gt;
TRANSFORMS-anonymizer = password-anonymizer&lt;/P&gt;

&lt;P&gt;[host::broker-*]&lt;BR /&gt;
TRANSFORMS-index = ClientRedirect&lt;BR /&gt;
TRUNCATE=0&lt;/P&gt;

&lt;P&gt;[host::client-*]&lt;BR /&gt;
TRANSFORMS-index = ClientRedirect&lt;BR /&gt;
TRUNCATE=0&lt;/P&gt;

&lt;P&gt;[host::pt*]&lt;BR /&gt;
TRANSFORMS-index = TrueFarmRedirect&lt;/P&gt;

&lt;P&gt;[host::st*]&lt;BR /&gt;
TRANSFORMS-index = TrueFarmRedirect&lt;/P&gt;

&lt;P&gt;[host::member-*]&lt;BR /&gt;
TRANSFORMS-index = MemberRedirect&lt;/P&gt;

&lt;P&gt;[host::doctor-*]&lt;BR /&gt;
TRANSFORMS-index = DoctorRedirect&lt;/P&gt;

&lt;P&gt;[host::www-*]&lt;BR /&gt;
TRANSFORMS-index = GlobalRedirect&lt;/P&gt;

&lt;P&gt;[host::sa-portals-*]&lt;BR /&gt;
TRANSFORMS-index = StrategicRedirect&lt;/P&gt;

&lt;P&gt;[source::udp:8514]&lt;BR /&gt;
TRANSFORMS-ClientHostOverride = ClientHostOverride&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
TRANSFORMS-ClientRawOverride = ClientRawOverride&lt;BR /&gt;
TRANSFORMS-ClientShRawOverride = ClientShRawOverride&lt;BR /&gt;
TRANSFORMS-ClientShortOverride = ClientShortOverride&lt;BR /&gt;
TRANSFORMS-ClientTempOverride = ClientTempOverride&lt;/P&gt;

&lt;P&gt;[source::udp:9514]&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TRANSFORMS-BrokerHostOverride = BrokerHostOverride&lt;BR /&gt;
TRANSFORMS-BrokerRawOverride = BrokerRawOverride&lt;BR /&gt;
TRANSFORMS-BrokerShRawOverride = BrokerShRawOverride&lt;BR /&gt;
TRANSFORMS-BrokerShortOverride = BrokerShortOverride&lt;BR /&gt;
TRANSFORMS-BrokerTempOverride = BrokerTempOverride&lt;/P&gt;

&lt;P&gt;shandman gravatar image&lt;BR /&gt;&lt;BR /&gt;
Answer by shandman&lt;BR /&gt;
53 minutes ago&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:13:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128310#M26345</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2020-09-28T18:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128311#M26346</link>
      <description>&lt;P&gt;For the multi-line events you need to configure the linebreaking.&lt;/P&gt;

&lt;P&gt;For the best performance use SHOULD_LINEMERGE = false &amp;amp; LINE_BREAKER in props.conf&lt;/P&gt;

&lt;P&gt;See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Indexmulti-lineevents" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Indexmulti-lineevents&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;When left to its own devices Splunk and SHOULD_LINEMERGE = true, Splunk will attempt to break on datestamps.&lt;/P&gt;

&lt;P&gt;When using LINE_BREAKER there needs to be a capturing group in the regex - eg &lt;CODE&gt;([\r\n]+)&lt;/CODE&gt; the default is any number of new lines or carriage returns. That denotes the end of the event and the start of a new one - the captured data is removed.&lt;/P&gt;

&lt;P&gt;For you, something like: &lt;BR /&gt;
props.conf&lt;BR /&gt;
&lt;CODE&gt;SHOULD_LINEMERGE = false&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;LINE_BREAKER = ([\r\n]+).*(?:\[\d{4}-\d{1,2}-\d{1,2}\s\d{1,2}:\d{1,2}:\d{1,2},\d*\])&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;TRUNCATE = 0&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;That should break on new lines that contain the date/timestamp in the square brackets.&lt;BR /&gt;
*note &lt;CODE&gt;(?:xxxx)&lt;/CODE&gt; is a non-capturing regex group, that data is not removed.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:13:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128311#M26346</guid>
      <dc:creator>eddit0r</dc:creator>
      <dc:date>2020-09-28T18:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunk logging truncates rather than wrapping to multiline?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128312#M26347</link>
      <description>&lt;P&gt;I tried adding that stanza and it still isn't working. Here is the results from the search.&lt;BR /&gt;
Splunk search criteria:   source=udp:9514 host=broker-p* "Broker Registration Info"&lt;/P&gt;

&lt;P&gt;broker-p3.vsp.com app=BrokerApp [2014-11-25 13:58:38,636] INFO  {abcdZw7rGW9P_gAWe8ONu} AppointmentCompleteAction.execute: Broker Registration Info: com.vsp.broker.model.AppointmentFormInfo@7ce1034f[licenses={0=com.vsp.broker.model.BrokerLicense@1e42d36e[state=MD,licenseNum=164213,effectiveDate=com.vsp.portal.util.Chrono@3546ea47[day=1,month=6,year=2014,value=,format=MMMM|dd#yyyy]], 1=com.vsp.broker.model.BrokerLicense@f75170b[state=PA,licenseNum=330247,effectiveDate=com.vsp.portal.util.Chrono@503bdb1a[day=3,month=3,year=2004,value=,format=MMMM|dd#yyyy]], 2=com.vsp.broker.model.BrokerLicense@abdcf8b[state=WV,licenseNum=6836793,effectiveDate=com.vsp.portal.util.Chrono@3384b42f[day=2,month=3,year=2002,value=,format=MMMM|dd#yyyy]], 3=com.vsp.broker.model.BrokerLicense@1aa29b40[state=,licenseNum=,effectiveDate=com.vsp.portal.util.Chrono@297e9469[day=,month=,year=,value=,format=MM...&lt;STRONG&gt;[Mag: Next line continuation is missing]&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2014 16:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunk-logging-truncates-rather-than-wrapping-to-multiline/m-p/128312#M26347</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2014-12-02T16:41:35Z</dc:date>
    </item>
  </channel>
</rss>

