<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index not getting the whole log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174968#M98282</link>
    <description>&lt;P&gt;one event per log,i set the sourcetype as  "util"&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2013 22:43:26 GMT</pubDate>
    <dc:creator>xisura</dc:creator>
    <dc:date>2013-12-11T22:43:26Z</dc:date>
    <item>
      <title>Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174962#M98276</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I have a problem in indexing of logs. After i search  by the source i found out that its not getting the whole content of the log file sample search =&amp;gt; index="test" source="sourcepath".&lt;BR /&gt;
I checked the raw log its complete but in splunk it shows incomplete logs.&lt;BR /&gt;
Please help how can i fix this?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
xisura&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 13:47:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174962#M98276</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-11T13:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174963#M98277</link>
      <description>&lt;P&gt;specification of the log that you want to get the contents of the input.conf correct?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 14:21:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174963#M98277</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2013-12-11T14:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174964#M98278</link>
      <description>&lt;P&gt;Any specific pattern for the missing entries?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 14:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174964#M98278</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-12-11T14:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174965#M98279</link>
      <description>&lt;P&gt;Hi Here's the sample log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;302051908 non-nice user cpu ticks
 67022224 nice user cpu ticks
474810206 system cpu ticks
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;7723346493 idle cpu ticks&lt;BR /&gt;
     10254021 IO-wait cpu ticks&lt;BR /&gt;
     21190725 IRQ cpu ticks&lt;BR /&gt;
    135816356 softirq cpu ticks&lt;BR /&gt;
   2438955853 interrupts&lt;BR /&gt;
    378813755 CPU context switches&lt;BR /&gt;
   1342633324 boot time&lt;BR /&gt;
    559999898 forks&lt;/P&gt;

&lt;P&gt;it cuts here..it didnt index the data below:&lt;/P&gt;

&lt;P&gt;DP:&lt;BR /&gt;
    2.13 : 29&lt;BR /&gt;
    3.9  : 29&lt;/P&gt;

&lt;P&gt;DPwithFR:&lt;BR /&gt;
    2.2  : 28&lt;BR /&gt;
    2.3  : 30&lt;BR /&gt;
    2.4  : 28&lt;BR /&gt;
    2.5  : 32&lt;BR /&gt;
    2.6  : 30&lt;BR /&gt;
    2.7  : 32&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 19:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174965#M98279</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-11T19:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174966#M98280</link>
      <description>&lt;P&gt;hi , the path to specific log in input.conf is correct&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 22:25:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174966#M98280</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-11T22:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174967#M98281</link>
      <description>&lt;P&gt;Is this the expected entire log file, or one event from a log file?&lt;BR /&gt;
What are you using as a sourcetype?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 22:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174967#M98281</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-11T22:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174968#M98282</link>
      <description>&lt;P&gt;one event per log,i set the sourcetype as  "util"&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 22:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174968#M98282</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-11T22:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174969#M98283</link>
      <description>&lt;P&gt;What is the sourcetype definition?  Can you post the props.conf stanza for &lt;CODE&gt;[util]&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 23:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174969#M98283</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-11T23:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174970#M98284</link>
      <description>&lt;P&gt;If I was Splunk, this log file would give me a headache.  There is no timestamp, the values come before the field sometimes and after the field name other times.  However, I am not Splunk.&lt;/P&gt;

&lt;P&gt;Regardless, I am new, so what I would do is just index the entire file as raw data and pull out what I wanted from the data with search time field extractions using rex or regex.&lt;/P&gt;

&lt;P&gt;To index the entire file without regard to field value content you will need to create a props.conf stanza that never line breaks like this:&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[util]
SHOULD_LINEMERGE=false
LINE_BREAKER=(?=!)
TRUNCATE=1000000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Reference: Old Folks et.al:&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/11566/how-can-i-index-config-files-and-text-documents-as-individual-events"&gt;http://answers.splunk.com/answers/11566/how-can-i-index-config-files-and-text-documents-as-individual-events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 23:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174970#M98284</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-11T23:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174971#M98285</link>
      <description>&lt;P&gt;Hi @lukejadamec, should i change the props.conf inside the apps folder or the one inside the systems/local ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 00:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174971#M98285</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-12T00:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174972#M98286</link>
      <description>&lt;P&gt;I would put it on the indexer in the splunk\etc\system\local\props.conf because it is easier to manage.  However, it should also work in the apps \local\props.conf just as well.&lt;BR /&gt;
If there are any props.conf files anywhere that have a stanza for &lt;CODE&gt;[util]&lt;/CODE&gt; you need to make sure the settings don't conflict, and I'd restart both the forwarder and indexer splunkd service just to make sure everything is fresh.&lt;BR /&gt;
Note: This change will only effect logs indexed after the restart.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 00:19:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174972#M98286</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-12T00:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174973#M98287</link>
      <description>&lt;P&gt;Here is a good read for answering questions regarding where to put/find which config:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/admin/Wheretofindtheconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 00:22:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174973#M98287</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-12T00:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174974#M98288</link>
      <description>&lt;P&gt;I already edit the props.conf and restart the indexer and the forwarder still it didnt show that part.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 01:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174974#M98288</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-12T01:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174975#M98289</link>
      <description>&lt;P&gt;I tried searching this sourcetype="util" "DPwithFR:" , set the time to all time, it shows it but the time is "July 19,2013"&lt;BR /&gt;
I suspect that its not getting the right time so i tried to convert the boot time which is in epoch time to standard time and it shows July 19,2013. Theres no latest data that shows that part , i also checked the raw logs and its there. I dont know why splunk didnt index that part.&lt;/P&gt;

&lt;P&gt;1342633324 boot time&lt;BR /&gt;
    565898104 forks&lt;BR /&gt;
DP:&lt;BR /&gt;
    2.13 : 34&lt;BR /&gt;
    3.9  : 33&lt;BR /&gt;
DPwithFR:&lt;BR /&gt;
    2.2  : 37&lt;BR /&gt;
    2.3  : 35&lt;BR /&gt;
    2.4  : 36&lt;BR /&gt;
    2.5  : 36&lt;BR /&gt;
    2.6  : 35&lt;BR /&gt;
    2.7  : 35&lt;BR /&gt;
    2.8  : 38&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 01:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174975#M98289</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-12T01:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174976#M98290</link>
      <description>&lt;P&gt;Try adding &lt;CODE&gt;DATETIME_CONFIG = NONE&lt;/CODE&gt; to the props.conf config, and remember this will only affect newly indexed logs after a restart.&lt;/P&gt;

&lt;P&gt;For reference:&lt;BR /&gt;
Set DATETIME_CONFIG = NONE to prevent the timestamp processor from running. When timestamp processing is off, Splunk does not look at the text of the event for the timestamp--it instead uses the event's "time of receipt"; in other words, the time the event is received via its input. For file-based inputs, this means that Splunk derives the event timestamp from the modification time of the input file.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 01:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174976#M98290</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-12T01:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: Index not getting the whole log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174977#M98291</link>
      <description>&lt;P&gt;ok , i'll keep you updated thanks for helping me  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2013 01:23:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-not-getting-the-whole-log/m-p/174977#M98291</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2013-12-12T01:23:51Z</dc:date>
    </item>
  </channel>
</rss>

