<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs with XML data is being read as two separate events by Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-with-XML-data-is-being-read-as-two-separate-events-by/m-p/533887#M89644</link>
    <description>&lt;P&gt;Hi There Folks!&lt;/P&gt;&lt;P&gt;Please refer screen shot of the original log file in a NotePad.&lt;BR /&gt;&lt;A href="http://prntscr.com/w82jd1" target="_blank" rel="noopener"&gt;http://prntscr.com/w82jd1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Although its one single event, as illustrated with a red line separator, Splunk UF is reading it as two separate events with diff time stamps.&amp;nbsp; I did read about MAX_EVENTS and TRUNCATE and my props.conf in UF and Indexer is updated to the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[default]&lt;BR /&gt;MAX_EVENTS = 100000&lt;BR /&gt;TRUNCATE = 100000&lt;BR /&gt;BREAK_ONLY_BEFORE_DATE = false&lt;/P&gt;&lt;P&gt;However, the problem persists. Any insights on what might be causing this issue?&amp;nbsp; Thanks for your help in advance.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Tue, 22 Dec 2020 20:33:57 GMT</pubDate>
    <dc:creator>venksel</dc:creator>
    <dc:date>2020-12-22T20:33:57Z</dc:date>
    <item>
      <title>Logs with XML data is being read as two separate events by Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-with-XML-data-is-being-read-as-two-separate-events-by/m-p/533887#M89644</link>
      <description>&lt;P&gt;Hi There Folks!&lt;/P&gt;&lt;P&gt;Please refer screen shot of the original log file in a NotePad.&lt;BR /&gt;&lt;A href="http://prntscr.com/w82jd1" target="_blank" rel="noopener"&gt;http://prntscr.com/w82jd1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Although its one single event, as illustrated with a red line separator, Splunk UF is reading it as two separate events with diff time stamps.&amp;nbsp; I did read about MAX_EVENTS and TRUNCATE and my props.conf in UF and Indexer is updated to the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[default]&lt;BR /&gt;MAX_EVENTS = 100000&lt;BR /&gt;TRUNCATE = 100000&lt;BR /&gt;BREAK_ONLY_BEFORE_DATE = false&lt;/P&gt;&lt;P&gt;However, the problem persists. Any insights on what might be causing this issue?&amp;nbsp; Thanks for your help in advance.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 20:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-with-XML-data-is-being-read-as-two-separate-events-by/m-p/533887#M89644</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2020-12-22T20:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Logs with XML data is being read as two separate events by Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-with-XML-data-is-being-read-as-two-separate-events-by/m-p/534119#M89669</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209614"&gt;@venksel&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Adding below TIME_PREFIX should help, Splunk is trying to guess event boundaries with timestamps. Since you have two timestamps in your event, you get two separate events.&lt;/P&gt;&lt;P&gt;You should put this props.conf to your indexer(s).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[xmlsourcetype]
TIME_PREFIX = [-]{12}[\r\n]+&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Dec 2020 20:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-with-XML-data-is-being-read-as-two-separate-events-by/m-p/534119#M89669</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-25T20:37:09Z</dc:date>
    </item>
  </channel>
</rss>

