<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What could be causing my ISE logs to split up and get miscategorized in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337081#M62227</link>
    <description>&lt;P&gt;thanks! I'm going to pop in the lookahead part right now and will see what happens, I'll report back tmw&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2017 00:00:21 GMT</pubDate>
    <dc:creator>lacrosse1991</dc:creator>
    <dc:date>2017-06-07T00:00:21Z</dc:date>
    <item>
      <title>What could be causing my ISE logs to split up and get miscategorized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337079#M62225</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I recently noticed that a small amount of ISE logs each day were getting split up. In order to remedy this, I adjusted the maximum log length on the ISE nodes to 1400 (it had previously been set to 1024). I thought this would at least make a little bit of a difference, but it does not appear to have improved at all. Is there anything else that I can change or check to help remedy this issue? &lt;/P&gt;

&lt;P&gt;An example of the logs can be found below. Notice how one event has a sourcetype of cisco:ise:syslog, while the other event has a generic sourcetype of syslog and is missing a timestamp&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3038i08AFC4135B37E099/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 13:38:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337079#M62225</guid>
      <dc:creator>lacrosse1991</dc:creator>
      <dc:date>2017-06-06T13:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: What could be causing my ISE logs to split up and get miscategorized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337080#M62226</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39580"&gt;@lacrosse1991&lt;/a&gt; It may be happenng because Splunk sees a timestamp further into the event on the field "ScheduledAt". By default we look 150 into the event for a timestamp. If that is the case you can set the following in props.conf on your indexer for this sourcetype to reduce how many characters Splunk looks into the event for the timestamp.&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/etc/system/local/props.conf&lt;BR /&gt;
[cisco:ise:syslog]&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 20&lt;/P&gt;

&lt;P&gt;If you still see the issue you can use LINE_BREAKER in props.conf&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Propsconf" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:23:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337080#M62226</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2020-09-29T14:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: What could be causing my ISE logs to split up and get miscategorized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337081#M62227</link>
      <description>&lt;P&gt;thanks! I'm going to pop in the lookahead part right now and will see what happens, I'll report back tmw&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 00:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337081#M62227</guid>
      <dc:creator>lacrosse1991</dc:creator>
      <dc:date>2017-06-07T00:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: What could be causing my ISE logs to split up and get miscategorized</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337082#M62228</link>
      <description>&lt;P&gt;for this to work, would I need to have the sourcetype for my input manually set to cisco:ise:syslog? I'm unfortunately still getting the same behavior. Thought I would check on the sourcetype part before I move forward with trying the line_breaker function. &lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 12:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-could-be-causing-my-ISE-logs-to-split-up-and-get/m-p/337082#M62228</guid>
      <dc:creator>lacrosse1991</dc:creator>
      <dc:date>2017-06-07T12:44:19Z</dc:date>
    </item>
  </channel>
</rss>

