<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk extracting a single event into 4 separate logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/540828#M90523</link>
    <description>&lt;P&gt;Currently using a UF to forward logs to Splunk.&lt;/P&gt;&lt;P&gt;Each .log file in the directory is 1 event but Splunk is separating each event into 4 separate logs.&lt;/P&gt;&lt;P&gt;I have added a custom app on the search head with a props.conf file as follows:&lt;/P&gt;&lt;P&gt;[RMAN]&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;LINE_BREAKER = ((*FAIL))&lt;BR /&gt;TRUNCATE = 99999999&lt;/P&gt;&lt;P&gt;Restarted Splunk but events are still separated into 4 events.&lt;/P&gt;&lt;P&gt;Anyone have any idea how to fix this.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2021 12:25:59 GMT</pubDate>
    <dc:creator>nathanluke86</dc:creator>
    <dc:date>2021-02-22T12:25:59Z</dc:date>
    <item>
      <title>Splunk extracting a single event into 4 separate logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/540828#M90523</link>
      <description>&lt;P&gt;Currently using a UF to forward logs to Splunk.&lt;/P&gt;&lt;P&gt;Each .log file in the directory is 1 event but Splunk is separating each event into 4 separate logs.&lt;/P&gt;&lt;P&gt;I have added a custom app on the search head with a props.conf file as follows:&lt;/P&gt;&lt;P&gt;[RMAN]&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;LINE_BREAKER = ((*FAIL))&lt;BR /&gt;TRUNCATE = 99999999&lt;/P&gt;&lt;P&gt;Restarted Splunk but events are still separated into 4 events.&lt;/P&gt;&lt;P&gt;Anyone have any idea how to fix this.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 12:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/540828#M90523</guid>
      <dc:creator>nathanluke86</dc:creator>
      <dc:date>2021-02-22T12:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extracting a single event into 4 separate logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/540836#M90525</link>
      <description>&lt;P&gt;To know whether the props.conf settings are correct requires some sample data.&amp;nbsp; Please share the same.&lt;/P&gt;&lt;P&gt;Props.conf settings for line breaking events must be installed on the indexer(s) rather than the search heads (unless you have a standalone installation).&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 13:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/540836#M90525</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-22T13:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extracting a single event into 4 separate logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/541107#M90558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/192656"&gt;@nathanluke86&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since you see 4 events, it is not TRUNCATE problem. LINE_BREAKER may not be enough, most probably the problem is TIME_PREFIX.&lt;/P&gt;&lt;P&gt;You should add TIME_PREFIX and TIME_FORMAT into your props.conf at indexers. If there is no TIME inside the event, you can use DATETIME_CONFIG = CURRENT&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 04:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-extracting-a-single-event-into-4-separate-logs/m-p/541107#M90558</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-24T04:38:49Z</dc:date>
    </item>
  </channel>
</rss>

