<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SHOULD_LINEMERGE = true and BREAK_ONLY_BEFORE_DATE = true defaults in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476935#M99770</link>
    <description>&lt;P&gt;Thanks!  So far so good.  I have not seen an incorrect merging of lines since I added TIME_FORMAT.  Will keep monitoring and will mark this as the answer soon.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2020 14:59:54 GMT</pubDate>
    <dc:creator>dglass0215</dc:creator>
    <dc:date>2020-01-09T14:59:54Z</dc:date>
    <item>
      <title>SHOULD_LINEMERGE = true and BREAK_ONLY_BEFORE_DATE = true defaults</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476933#M99768</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;i am trying to understand the documentation surrounding SHOULD_LINEMERGE.  It says the default is SHOULD_LINEMERGE = true and BREAK_ONLY_BEFORE_DATE = true.  If my understanding is correct this means that if a logfile has multiple lines, the multiple lines will be part of one event that is indexed up until the next date/timestamp is found and then that would be another event.&lt;/P&gt;

&lt;P&gt;I have a logfile with the following two lines:&lt;/P&gt;

&lt;P&gt;2019-12-30 09:16:41:908: Requestor: IMM_Mobile, IsLocal: False&lt;BR /&gt;
2019-12-30 09:16:41:908: 637132942019089151: Scanned CID: BARCODE:&lt;/P&gt;

&lt;P&gt;However, they get indexed as one event and this is not what I want.  A previous suggestion to me was to make SHOULD_LINEMERGE = false, however I do not think I want to do that because there are certain entries in the logfile that do span multiple lines.&lt;/P&gt;

&lt;P&gt;Any assistance is greatly appreciated!&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476933#M99768</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2020-09-30T03:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: SHOULD_LINEMERGE = true and BREAK_ONLY_BEFORE_DATE = true defaults</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476934#M99769</link>
      <description>&lt;P&gt;Your understanding of those two settings is correct.  It's important, however, to define what constitutes a date.  Add &lt;CODE&gt;TIME_FORMAT = %Y-%m-%d %H:%M:%S:%3N&lt;/CODE&gt; to the appropriate props.conf file.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 18:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476934#M99769</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-08T18:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: SHOULD_LINEMERGE = true and BREAK_ONLY_BEFORE_DATE = true defaults</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476935#M99770</link>
      <description>&lt;P&gt;Thanks!  So far so good.  I have not seen an incorrect merging of lines since I added TIME_FORMAT.  Will keep monitoring and will mark this as the answer soon.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 14:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SHOULD-LINEMERGE-true-and-BREAK-ONLY-BEFORE-DATE-true-defaults/m-p/476935#M99770</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2020-01-09T14:59:54Z</dc:date>
    </item>
  </channel>
</rss>

