<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Eating in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30257#M5277</link>
    <description>&lt;P&gt;Change &lt;CODE&gt;MAX_EVENTS&lt;/CODE&gt; for your sourcetype in props.conf.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MAX_EVENTS = &amp;lt;integer&amp;gt;
* Specifies the maximum number of input lines to add to any event.
* Splunk breaks after the specified number of lines are read.
* Defaults to 256 (lines).
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 07 Dec 2011 17:46:41 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-12-07T17:46:41Z</dc:date>
    <item>
      <title>File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30256#M5276</link>
      <description>&lt;P&gt;I am eating NESSUS.V1 files from our Nessus contiues monitoring system&lt;/P&gt;

&lt;P&gt;Nessus puts the output from the scan in XML format in the v1 files and the indivitule system info is put in a one event format when it is read into Splunk indexer.&lt;/P&gt;

&lt;P&gt;The problem is some of the events are more than 257 lines and Splunk is truncating the events at 257.&lt;BR /&gt;&lt;BR /&gt;
Then I lose some of the event integrity and I have to go look at the very next event to get the rest of the data.  &lt;/P&gt;

&lt;P&gt;How can I increase the number of lines for this source or source type?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 17:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30256#M5276</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-12-07T17:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30257#M5277</link>
      <description>&lt;P&gt;Change &lt;CODE&gt;MAX_EVENTS&lt;/CODE&gt; for your sourcetype in props.conf.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;MAX_EVENTS = &amp;lt;integer&amp;gt;
* Specifies the maximum number of input lines to add to any event.
* Splunk breaks after the specified number of lines are read.
* Defaults to 256 (lines).
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Dec 2011 17:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30257#M5277</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-12-07T17:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30258#M5278</link>
      <description>&lt;P&gt;Also, I would be very interested to hear what you're doing and what you want to do with Nessus reports in Splunk. I'm in the process of creating an app for Nessus and some other vulnerability scanners so I'm very thankful for all input!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 17:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30258#M5278</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-12-07T17:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30259#M5279</link>
      <description>&lt;P&gt;thanks Ayn,&lt;/P&gt;

&lt;P&gt;I found this post after I asked the question&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/6764/events-chunked-into-256-lines"&gt;http://splunk-base.splunk.com/answers/6764/events-chunked-into-256-lines&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 17:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30259#M5279</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-12-07T17:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30260#M5280</link>
      <description>&lt;P&gt;Ayn,&lt;/P&gt;

&lt;P&gt;Do you think I should modify the props.conf in the universal forwarder app "/etc/deployment-apps/appName/Local" or the indexer "etc/system/local" ?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 18:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30260#M5280</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-12-07T18:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30261#M5281</link>
      <description>&lt;P&gt;Line breaking is done on the indexer, so that's where the props.conf changes should go.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 18:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30261#M5281</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-12-07T18:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30262#M5282</link>
      <description>&lt;P&gt;Well, line breaking hapens whereever the parsing occurs. With a Universal Forwarder, it is indeed on the indexer, but details are: &lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 18:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30262#M5282</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-12-07T18:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: File Eating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30263#M5283</link>
      <description>&lt;P&gt;Well in this case it was either on a UF or an indexer, so...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 20:35:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Eating/m-p/30263#M5283</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-12-07T20:35:08Z</dc:date>
    </item>
  </channel>
</rss>

