<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event Breaking Issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251314#M99182</link>
    <description>&lt;P&gt;Thanks Woodcock, for your inputs!&lt;/P&gt;</description>
    <pubDate>Tue, 06 Oct 2015 08:18:07 GMT</pubDate>
    <dc:creator>bharathkumarnec</dc:creator>
    <dc:date>2015-10-06T08:18:07Z</dc:date>
    <item>
      <title>Event Breaking Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251312#M99180</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;Need help regarding event breaking, below is my current scenario:&lt;/P&gt;

&lt;P&gt;One my log file in the indexer is updating not updating the log in frequent intervals, for example:&lt;/P&gt;

&lt;P&gt;Event starts with date in format "2015-10-01 07:31:09.733+0000" and this event will end writing data after 5min with 'n' number of lines, and next event will start with the same date format. The problem is as the log is taking 5min time to finish writing the event, splunk splitting one event into three or four different events.&lt;/P&gt;

&lt;P&gt;Kindly help me out with this problem, let me know if more information is required.&lt;/P&gt;

&lt;P&gt;Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 09:13:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251312#M99180</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2015-10-01T09:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251313#M99181</link>
      <description>&lt;P&gt;You can try using the &lt;CODE&gt;time_before_close&lt;/CODE&gt; parameter inside &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and setting it to something like &lt;CODE&gt;300&lt;/CODE&gt; but be sure to test it on one server/file first and if you decide to keep it, be sure it is only on these kinds of inputs because this will cause a 5-minute delay in getting events into Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 17:58:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251313#M99181</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-05T17:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251314#M99182</link>
      <description>&lt;P&gt;Thanks Woodcock, for your inputs!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2015 08:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251314#M99182</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2015-10-06T08:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251315#M99183</link>
      <description>&lt;P&gt;The usage of this parameter is working fine for me..Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2015 20:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-Issue/m-p/251315#M99183</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2015-10-17T20:04:24Z</dc:date>
    </item>
  </channel>
</rss>

