<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexing time is too long in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429749#M75274</link>
    <description>&lt;P&gt;Thank you for your response I'll share the config&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jun 2018 09:39:59 GMT</pubDate>
    <dc:creator>Kawtar</dc:creator>
    <dc:date>2018-06-01T09:39:59Z</dc:date>
    <item>
      <title>Indexing time is too long</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429746#M75271</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;In my props.conf, I added , BREAK_ONLY_BEFORE= regex  AND LINE_BREAKER_REGEX , and I see that time of indexing is too long, the universal forwarder detect the files but it index it 4 ou 5 min after, but when I removed BREAK_ONLY_BEFORE and LINE_BREAKER_REGEX from the config file: props.conf, It indexed very quick . Any explications plz ? &lt;/P&gt;

&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429746#M75271</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2020-09-29T19:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing time is too long</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429747#M75272</link>
      <description>&lt;P&gt;It means your event parsing configurations are no efficient and causing delay in indexing (mostly delay in parsing layer). Please share your current props.conf entry for your sourcetype (assuming it was setup in Index/heavy forwarder) and some sample log entries. Based on that, Splunker's here can suggest you efficient config to put in your props.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 29 May 2018 17:51:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429747#M75272</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-05-29T17:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing time is too long</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429748#M75273</link>
      <description>&lt;P&gt;How complex are your regex strings?  Have you tried only one of BREAK_ONLY_BEFORE and LINE_BREAKER_REGEX?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429748#M75273</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-29T19:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing time is too long</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429749#M75274</link>
      <description>&lt;P&gt;Thank you for your response I'll share the config&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 09:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429749#M75274</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2018-06-01T09:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing time is too long</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429750#M75275</link>
      <description>&lt;P&gt;I noticed when I use BREAK_ONLY_BEFORE Indexing time is too long but when I use LINE_BREAKER_REGEX fast than the parameter break_only_before, can you confirm that ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429750#M75275</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2020-09-29T19:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing time is too long</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429751#M75276</link>
      <description>&lt;P&gt;I haven't noticed this so I can't confirm it.  I rarely use BREAK_ONLY_BEFORE so I can't say if it's slower than LINE_BREAKER.  If only BREAK_ONLY_BEFORE works for your data and its performance is bad, I suggest you open a support case.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-time-is-too-long/m-p/429751#M75276</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-29T19:48:31Z</dc:date>
    </item>
  </channel>
</rss>

