<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we getting  &amp;quot;Changing breaking behavior for event stream because MAX_EVENTS (256) was exceeded without a single event break&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-quot-Changing-breaking-behavior-for-event/m-p/498752#M84997</link>
    <description>&lt;P&gt;I believe we found the issue: extra spaces in the stanaza's name before d_ and after y:&lt;BR /&gt;
&lt;CODE&gt;[ d_tmp_storage_history ]&lt;/CODE&gt;.  After we deleted spaces and pushed the props.conf, it seemed to correct the issue&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2020 03:07:01 GMT</pubDate>
    <dc:creator>mlevsh</dc:creator>
    <dc:date>2020-03-24T03:07:01Z</dc:date>
    <item>
      <title>Why are we getting  "Changing breaking behavior for event stream because MAX_EVENTS (256) was exceeded without a single event break"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-quot-Changing-breaking-behavior-for-event/m-p/498751#M84996</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have started to experience line breaking issue  for  our csv source. As a result  sometimes we have an attempt from Splunk to read a whole cvs file with 500+ lines  as one event up to 256 lines  in it.  Then these errors occur and Splunk starts reading the rest of the file correctly: one line per one event. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;AggregatorMiningProcessor - Changing breaking behavior for event stream because MAX_EVENTS (256) was exceeded without a single event break. Will set BREAK_ONLY_BEFORE_DATE to False, and unset any MUST_NOT_BREAK_BEFORE or MUST_NOT_BREAK_AFTER rules. Typically this will amount to treating this data as single-line only. - data_source="/tmp/tmp-in/tmp/d_tmp_storage_history.csv", data_host="host06", data_sourcetype="d_tmp_storage_history"
host = hf_host  source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd

WARN  AggregatorMiningProcessor - Breaking event because limit of 256 has been exceeded - data_source="/tmp/tmp-in/tmp/d_tmp_storage_history.csv", data_host="host06", data_sourcetype="d_tmp_storage_history"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The issue seems to be started few days ago. No known changes were introduced on Splunk side or on the side that runs scripts to generate cvs files we monitor.&lt;/P&gt;

&lt;P&gt;Here is  props.conf we use on Splunk Universal Forwarder on data_host="host06" that monitors data_source="/tmp/tmp-in/tmp/d_tmp_storage_history.csv" &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ d_tmp_storage_history ]
HEADER_FIELD_LINE_NUMBER = 1
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
INDEXED_EXTRACTIONS=csv
KV_MODE=none
DATETIME_CONFIG=CURRENT
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We have checked csv file via Excel ,Notepad+  ,vi editor for hidden characters (:set list), cat with -v -t -e - to see if some special unusual character(s)  pop up. Haven't found anything unusual&lt;/P&gt;

&lt;P&gt;Any advice which direction to look would be appreciated!&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:40:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-quot-Changing-breaking-behavior-for-event/m-p/498751#M84996</guid>
      <dc:creator>mlevsh</dc:creator>
      <dc:date>2020-09-30T04:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting  "Changing breaking behavior for event stream because MAX_EVENTS (256) was exceeded without a single event break"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-quot-Changing-breaking-behavior-for-event/m-p/498752#M84997</link>
      <description>&lt;P&gt;I believe we found the issue: extra spaces in the stanaza's name before d_ and after y:&lt;BR /&gt;
&lt;CODE&gt;[ d_tmp_storage_history ]&lt;/CODE&gt;.  After we deleted spaces and pushed the props.conf, it seemed to correct the issue&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 03:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-quot-Changing-breaking-behavior-for-event/m-p/498752#M84997</guid>
      <dc:creator>mlevsh</dc:creator>
      <dc:date>2020-03-24T03:07:01Z</dc:date>
    </item>
  </channel>
</rss>

