<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log events are being merged for few cases in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514572#M87190</link>
    <description>&lt;P&gt;Thanks for your input&lt;/P&gt;&lt;P&gt;so i was missing the start of line in my regex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2020 01:49:43 GMT</pubDate>
    <dc:creator>mv059</dc:creator>
    <dc:date>2020-08-18T01:49:43Z</dc:date>
    <item>
      <title>Log events are being merged for few cases</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514557#M87186</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am facing a challenge with some of the splunk logs being merged as a one event.&lt;/P&gt;&lt;P&gt;I have tried breaking them by updating below in splunk forwarder config but doesnt't work.&lt;/P&gt;&lt;P&gt;can someone suggest what i am missing here&lt;/P&gt;&lt;P&gt;props.conf&amp;nbsp; in&amp;nbsp; local&lt;/P&gt;&lt;P&gt;########## APPLICATION SERVERS ######&lt;BR /&gt;[default]&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[event_logservice]&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;LINE_BREAKER= (\d{4}-\d{2}-\d{2}\s+\d+:\d+:\d+.\d+\s+-\d+\s+Event)&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 75&lt;BR /&gt;TRUNCATE = 0&lt;/P&gt;&lt;P&gt;Additional details : Logs are being written to files by logstash and then forwarder is reading and pushing data&lt;/P&gt;&lt;P&gt;My log file :&lt;/P&gt;&lt;P&gt;2020-08-17 14:49:21.161 -0700 Event log_level="info" build_id="HEAD (d3b8457cc9)" bzdate="20200817" serial_no="KJST45HSS" register="ABC" sessionId="KJST45HSS_20200817_144739196_1" wid="H34-vx-841D6B9C-8158-4975-9AB3-FDB5E9FD80E8" component="Manager" message="adding "&lt;BR /&gt;2020-08-17 14:49:21.163 -0700 Event log_level="info" build_id="HEAD (d3b8457cc9)" bzdate="20200817" serial_no="KJST45HSS" register="ABC" sessionId="KJST45HSS_20200817_144739196_1" wid="H34-vx-841D6B9C-8158-4975-9AB3-FDB5E9FD80E8" component="Manager" message="adding completion "&lt;/P&gt;&lt;P&gt;** example above 2 rows and shown merged in splunk.. and it is happending randomly for other log events also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 22:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514557#M87186</guid>
      <dc:creator>mv059</dc:creator>
      <dc:date>2020-08-17T22:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Log events are being merged for few cases</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514565#M87188</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;[event_logservice]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SHOULD_LINEMERGE = false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;LINE_BREAKER= ([\r\n]+)\d{4}-\d{2}-\d{2}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MAX_TIMESTAMP_LOOKAHEAD = 75&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TRUNCATE = 0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 23:13:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514565#M87188</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-08-17T23:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Log events are being merged for few cases</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514572#M87190</link>
      <description>&lt;P&gt;Thanks for your input&lt;/P&gt;&lt;P&gt;so i was missing the start of line in my regex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 01:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-events-are-being-merged-for-few-cases/m-p/514572#M87190</guid>
      <dc:creator>mv059</dc:creator>
      <dc:date>2020-08-18T01:49:43Z</dc:date>
    </item>
  </channel>
</rss>

