<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default LINE_BREAKER broken? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209458#M41260</link>
    <description>&lt;P&gt;Nothing has been changed in the default directory. The props.conf file is dated 5/12/2016 just like all the other default files that were put in place by the 6.4.1 upgrade. The previous default files (6.3.3) were all dated 4/28/2015 and that old props.conf file also had SHOULD_LINEMERGE set to true.&lt;/P&gt;

&lt;P&gt;From props.conf.spec:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;SHOULD_LINEMERGE = [true|false]&lt;BR /&gt;
* When set to true, Splunk combines several lines of data into a single&lt;BR /&gt;
  multiline event, based on the following configuration attributes.&lt;BR /&gt;
* *Defaults to true.&lt;/EM&gt;*&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2016 15:28:22 GMT</pubDate>
    <dc:creator>cwilmoth</dc:creator>
    <dc:date>2016-06-14T15:28:22Z</dc:date>
    <item>
      <title>Default LINE_BREAKER broken?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209454#M41256</link>
      <description>&lt;P&gt;We recently upgraded from 6.3.3 to 6.4.1 in an attempt to fix some performance issues. After upgrading, there were a ton of &lt;STRONG&gt;"Changing breaking behavior for event stream because MAX_EVENTS (256) was exceeded without a single event break..."&lt;/STRONG&gt; for multiple data sources on our heavy forwarders. I struggled to figure out why and eventually just created a [default] stanza in the props.conf file that gets deployed to both of our heavy forwarders and put the default &lt;STRONG&gt;LINE_BREAKER = ([\r\n]+)&lt;/STRONG&gt; in there. After deployment, events are breaking just fine (like they were before). &lt;/P&gt;

&lt;P&gt;Is this a known issue? I did not see anything in the release notes.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 21:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209454#M41256</guid>
      <dc:creator>cwilmoth</dc:creator>
      <dc:date>2016-06-13T21:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Default LINE_BREAKER broken?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209455#M41257</link>
      <description>&lt;P&gt;Run &lt;CODE&gt;$SPLUNK_HOME/bin/splunk cmd btool --debug props list that_sourcetype&lt;/CODE&gt; with and without the extra default stanza and compare the output.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 22:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209455#M41257</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-06-13T22:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Default LINE_BREAKER broken?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209456#M41258</link>
      <description>&lt;P&gt;&lt;STRONG&gt;With:&lt;/STRONG&gt;&lt;BR /&gt;
F:\Splunk\etc\apps\Dso_deploy_hvy_fwdrs\default\props.conf [deepsecurity-system_events]&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    ANNOTATE_PUNCT = True&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    AUTO_KV_JSON = true&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    BREAK_ONLY_BEFORE = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    CHARSET = AUTO&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    DATETIME_CONFIG = \etc\datetime.xml&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    HEADER_MODE = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    LEARN_SOURCETYPE = true&lt;BR /&gt;
&lt;STRONG&gt;F:\Splunk\etc\apps\Dso_deploy_hvy_fwdrs\default\props.conf LINE_BREAKER = ([\r\n]+)&lt;/STRONG&gt;&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
F:\Splunk\etc\system\local\props.conf                      MAX_DAYS_AGO = 90&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_DAYS_HENCE = 2&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_EVENTS = 256&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MUST_BREAK_AFTER = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MUST_NOT_BREAK_AFTER = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MUST_NOT_BREAK_BEFORE = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION = indexing&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-all = full&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-inner = inner&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-outer = outer&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-raw = none&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-standard = standard&lt;BR /&gt;
F:\Splunk\etc\apps\Dso_deploy_hvy_fwdrs\default\props.conf SHOULD_LINEMERGE = false&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    TRANSFORMS = &lt;BR /&gt;
F:\Splunk\etc\apps\rb_steelhead_ta\default\props.conf      TRANSFORMS-riverbed_src = riverbed_src&lt;BR /&gt;
F:\Splunk\etc\apps\Dso_deploy_hvy_fwdrs\default\props.conf TRANSFORMS-t3 = set-tm-fw-sourcetype,set-tm-log-sourcetype,set-tm-im-sourcetype,set-tm-ip-sourcetype,set-tm-ipsevents&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    TRUNCATE = 10000&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    detect_trailing_nulls = auto&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    maxDist = 100&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    priority = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    sourcetype = &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Without:&lt;/STRONG&gt;&lt;BR /&gt;
F:\Splunk\etc\apps\Dso_deploy_hvy_fwdrs\default\props.conf [deepsecurity-system_events]&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    ANNOTATE_PUNCT = True&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    AUTO_KV_JSON = true&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    BREAK_ONLY_BEFORE = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    CHARSET = AUTO&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    DATETIME_CONFIG = \etc\datetime.xml&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    HEADER_MODE = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    LEARN_SOURCETYPE = true&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    LINE_BREAKER_LOOKBEHIND = 100&lt;BR /&gt;
F:\Splunk\etc\system\local\props.conf                      MAX_DAYS_AGO = 90&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_DAYS_HENCE = 2&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_DIFF_SECS_AGO = 3600&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_DIFF_SECS_HENCE = 604800&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_EVENTS = 256&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MAX_TIMESTAMP_LOOKAHEAD = 128&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MUST_BREAK_AFTER = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MUST_NOT_BREAK_AFTER = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    MUST_NOT_BREAK_BEFORE = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION = indexing&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-all = full&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-inner = inner&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-outer = outer&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-raw = none&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SEGMENTATION-standard = standard&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    SHOULD_LINEMERGE = True&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    TRANSFORMS = &lt;BR /&gt;
F:\Splunk\etc\apps\rb_steelhead_ta\default\props.conf      TRANSFORMS-riverbed_src = riverbed_src&lt;BR /&gt;
F:\Splunk\etc\apps\Dso_deploy_hvy_fwdrs\default\props.conf TRANSFORMS-t3 = set-tm-fw-sourcetype,set-tm-log-sourcetype,set-tm-im-sourcetype,set-tm-ip-sourcetype,set-tm-ipsevents&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    TRUNCATE = 10000&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    detect_trailing_nulls = auto&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    maxDist = 100&lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    priority = &lt;BR /&gt;
F:\Splunk\etc\system\default\props.conf                    sourcetype = &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209456#M41258</guid>
      <dc:creator>cwilmoth</dc:creator>
      <dc:date>2020-09-29T09:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Default LINE_BREAKER broken?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209457#M41259</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;The problem is that you configured the F:\Splunk\etc\system\default\props.conf SHOULD_LINEMERGE  in the default directory.&lt;BR /&gt;
You should never change the configuration in this directory becouse when you upgrade splunk overwrite default files.&lt;/P&gt;

&lt;P&gt;Hope i help you &lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 14:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209457#M41259</guid>
      <dc:creator>jmallorquin</dc:creator>
      <dc:date>2016-06-14T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Default LINE_BREAKER broken?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209458#M41260</link>
      <description>&lt;P&gt;Nothing has been changed in the default directory. The props.conf file is dated 5/12/2016 just like all the other default files that were put in place by the 6.4.1 upgrade. The previous default files (6.3.3) were all dated 4/28/2015 and that old props.conf file also had SHOULD_LINEMERGE set to true.&lt;/P&gt;

&lt;P&gt;From props.conf.spec:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;SHOULD_LINEMERGE = [true|false]&lt;BR /&gt;
* When set to true, Splunk combines several lines of data into a single&lt;BR /&gt;
  multiline event, based on the following configuration attributes.&lt;BR /&gt;
* *Defaults to true.&lt;/EM&gt;*&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 15:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209458#M41260</guid>
      <dc:creator>cwilmoth</dc:creator>
      <dc:date>2016-06-14T15:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Default LINE_BREAKER broken?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209459#M41261</link>
      <description>&lt;P&gt;There's a second change, the without list has should linemerge set to true while the with list has it set to false. This tells Splunk to merge lines back together to whole events after applying the line breaker. Try setting should linemerge to false without setting the line breaker.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 16:32:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-LINE-BREAKER-broken/m-p/209459#M41261</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-06-14T16:32:10Z</dc:date>
    </item>
  </channel>
</rss>

