<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events not breaking correctly - using mv-add in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217618#M42847</link>
    <description>&lt;P&gt;Your props.conf does not specify  &lt;CODE&gt;MAX_EVENTS&lt;/CODE&gt; - which defaults to 256. So, when you have an event with many, many lines, Splunk breaks even without a &lt;CODE&gt;--&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Add this to the props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MAX_EVENTS = 1024
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or some other number that is larger than the maximum possible number of events. Setting &lt;CODE&gt;TRUNCATE&lt;/CODE&gt; would not have solved this problem anyway.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2016 19:22:44 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2016-01-07T19:22:44Z</dc:date>
    <item>
      <title>Events not breaking correctly - using mv-add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217614#M42843</link>
      <description>&lt;P&gt;Hello Splunkers.&lt;/P&gt;

&lt;P&gt;I'm helping a client to find out why some of his events are not being broken correctly.&lt;BR /&gt;
They are currently running a Search Head Cluster with 3 SHs, 2 Indexers, 1 Master Cluster and 1 License/Deployer.&lt;BR /&gt;
Here is a example of log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;--
tstamp="20160105 23:59:39.893"
IdCmd=01
Port=01
tstampResp="20160105 23:59:40.390"
Cmd="XXXXXX"
tipoAcao=ABC
Pri=I
Rsgmt=H
mainkey=12345678
acao="A";vAcao="000100000000A";resp="O"
acao="A";vAcao="000200000000A";resp="O"
acao="A";vAcao="000300000000A";resp="O"
acao="A";vAcao="000400000000A";resp="O"
acao="A";vAcao="000500000000A";resp="O"
acao="A";vAcao="000600000000A";resp="O"
acao="A";vAcao="000700000000A";resp="O"
acao="A";vAcao="000800000000A";resp="O"
acao="A";vAcao="000900000000A";resp="O"
acao="A";vAcao="001000000000A";resp="O"
acao="A";vAcao="001100000000A";resp="O"
acao="A";vAcao="001200000000A";resp="O"
acao="A";vAcao="001300000000A";resp="O"
acao="A";vAcao="001400000000A";resp="O"
acao="A";vAcao="001500000000A";resp="O"
acao="A";vAcao="001600000000A";resp="O"
acao="A";vAcao="006700000000A";resp="O"
acao="A";vAcao="006A00000000A";resp="O"
acao="A";vAcao="006B00000000A";resp="O"
acao="A";vAcao="006C00000000A";resp="O"
acao="A";vAcao="006E00000000A";resp="O"
acao="A";vAcao="006F00000000A";resp="O"
acao="A";vAcao="007000000000A";resp="O"
acao="A";vAcao="007200000000A";resp="O"
acao="A";vAcao="007400000000A";resp="O"
acao="A";vAcao="007500000000A";resp="O"
acao="A";vAcao="007600000000A";resp="O"
acao="A";vAcao="007700000000A";resp="O"
acao="A";vAcao="007800000000A";resp="O"
acao="A";vAcao="007900000000A";resp="O"
acao="A";vAcao="007B00000000A";resp="O"
acao="A";vAcao="007E00000000A";resp="O"
acao="A";vAcao="008000000000A";resp="O"
acao="A";vAcao="008200000000A";resp="O"
acao="A";vAcao="008900000000A";resp="O"
acao="A";vAcao="008A00000000A";resp="O"
acao="A";vAcao="008E00000000A";resp="O"
acao="A";vAcao="008F00000000A";resp="O"
acao="A";vAcao="009800000000A";resp="O"
acao="A";vAcao="009B00000000A";resp="O"
acao="A";vAcao="009D00000000A";resp="O"
acao="A";vAcao="009F00000000A";resp="O"
acao="A";vAcao="00A000000000A";resp="O"
acao="A";vAcao="00AA00000000A";resp="O"
acao="A";vAcao="00AB00000000A";resp="O"
acao="A";vAcao="00AC00000000A";resp="O"
acao="A";vAcao="00B500000000A";resp="O"
acao="A";vAcao="00C000000000A";resp="O"
acao="A";vAcao="00C100000000A";resp="O"
acao="A";vAcao="00C200000000A";resp="O"
acao="A";vAcao="01AA00000000A";resp="O"
acao="A";vAcao="021100000000A";resp="O"
acao="A";vAcao="021200000000A";resp="O"
acao="A";vAcao="039100000000A";resp="O"
acao="A";vAcao="039C00000000A";resp="O"
acao="A";vAcao="01C100000000A";resp="O"
acao="A";vAcao="000500000000A";resp="O"
acao="A";vAcao="001400000000A";resp="O"
acao="A";vAcao="005300000000A";resp="O"
acao="A";vAcao="005C00000000A";resp="O"
acao="A";vAcao="008400000000A";resp="O"
acao="A";vAcao="001600000000A";resp="O"
acao="A";vAcao="00F300000000A";resp="O"
acao="A";vAcao="00F000000000A";resp="O"
acao="A";vAcao="01C200000000A";resp="O"
acao="A";vAcao="00EF00000000A";resp="O"
acao="A";vAcao="01C300000000A";resp="O"
acao="A";vAcao="01C400000000A";resp="O"
acao="A";vAcao="00EE00000000A";resp="O"
acao="A";vAcao="01C600000000A";resp="O"
acao="A";vAcao="01C500000000A";resp="O"
acao="A";vAcao="01D700000000A";resp="O"
acao="A";vAcao="00EC00000000A";resp="O"
acao="A";vAcao="01C700000000A";resp="O"
acao="A";vAcao="00ED00000000A";resp="O"
acao="A";vAcao="01DE00000000A";resp="O"
acao="A";vAcao="01DD00000000A";resp="O"
acao="A";vAcao="01E200000000A";resp="O"
acao="A";vAcao="01C800000000A";resp="O"
acao="A";vAcao="01E100000000A";resp="O"
acao="A";vAcao="01E000000000A";resp="O"
acao="A";vAcao="01C900000000A";resp="O"
acao="A";vAcao="01CA00000000A";resp="O"
acao="A";vAcao="00F400000000A";resp="O"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The log above always starts with &lt;CODE&gt;--&lt;/CODE&gt; and can have hundreads of &lt;CODE&gt;acao="A";vAcao="XXXX00000000A";resp="O"&lt;/CODE&gt; lines.&lt;BR /&gt;
Here is the &lt;EM&gt;props.conf&lt;/EM&gt; that I'm using:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SHOULD_LINEMERGE=true
NO_BINARY_CHECK=true
BREAK_ONLY_BEFORE=--
disabled=false
TIME_PREFIX=\d+\=\"
TIME_FORMAT=%Y%m%d %H:%M:%S.%3N
MAX_TIMESTAMP_LOOKAHEAD=30
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And here is the &lt;EM&gt;transforms.conf&lt;/EM&gt; that I'm using:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;REGEX = acao=\"(.*?)\";vAcao=\"(.*?)\";resp=\"(.*?)\" 
FORMAT = acao::$1 vAcao::$2 resp::$3 
MV_ADD = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sometimes, the event is not broken correctly. It breaks on &lt;CODE&gt;acao="A";vAcao="XXXX00000000A";resp="O"&lt;/CODE&gt; lines.&lt;BR /&gt;
I thought that I should include the &lt;STRONG&gt;TRUNCATE&lt;/STRONG&gt; option in my &lt;EM&gt;props.conf&lt;/EM&gt;.&lt;BR /&gt;
However, when I try to &lt;EM&gt;Distribute Bundle Configuration&lt;/EM&gt; using the UI at the Master, I receive an error message saying that I can't use TRUNCATE at my stanza.&lt;BR /&gt;
So now I'm a bit lost.&lt;BR /&gt;
Do you guys have any ideias that can help me?&lt;/P&gt;

&lt;P&gt;Od course I can go directly to the Indexers and put the TRUNCATE option "by hand", but since they will soon add more indexers, this will not be feasible without the Master's Distribute Bundle Configuration.&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;BR /&gt;
Regards,&lt;BR /&gt;
GMA&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217614#M42843</guid>
      <dc:creator>guimilare</dc:creator>
      <dc:date>2016-01-07T18:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Events not breaking correctly - using mv-add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217615#M42844</link>
      <description>&lt;P&gt;From where you're ingesting this log? Is it a data monitoring setup on Search Head OR on a Forwarder? Which location you're putting the props.conf for the sourcetype (with TRUNCATE)?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:51:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217615#M42844</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-01-07T18:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Events not breaking correctly - using mv-add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217616#M42845</link>
      <description>&lt;P&gt;Hi somesoni2. I'm getting this data on a Forwarder.  /opt/splunk/etc/master-apps/app/local/props.conf is the path on the Master. When I use Truncate, I can't use the Distribute Bundle Configuration on Master's UI.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217616#M42845</guid>
      <dc:creator>guimilare</dc:creator>
      <dc:date>2016-01-07T18:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Events not breaking correctly - using mv-add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217617#M42846</link>
      <description>&lt;P&gt;Are you able to push the bundle from the command line/shell on the Indexer Master?? using &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Indexer/Updatepeerconfigurations#3._Apply_the_bundle_to_the_peers"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Indexer/Updatepeerconfigurations#3._Apply_the_bundle_to_the_peers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 19:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217617#M42846</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-01-07T19:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Events not breaking correctly - using mv-add</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217618#M42847</link>
      <description>&lt;P&gt;Your props.conf does not specify  &lt;CODE&gt;MAX_EVENTS&lt;/CODE&gt; - which defaults to 256. So, when you have an event with many, many lines, Splunk breaks even without a &lt;CODE&gt;--&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Add this to the props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MAX_EVENTS = 1024
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or some other number that is larger than the maximum possible number of events. Setting &lt;CODE&gt;TRUNCATE&lt;/CODE&gt; would not have solved this problem anyway.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 19:22:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Events-not-breaking-correctly-using-mv-add/m-p/217618#M42847</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-01-07T19:22:44Z</dc:date>
    </item>
  </channel>
</rss>

