<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Linemerging timer? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51119#M43867</link>
    <description>&lt;P&gt;Does Splunk have an internal timer when doing line merging?&lt;/P&gt;

&lt;P&gt;For example, if I'm doing line merging (SHOULD_LINEMERGE=true) with correct date parsing field, and events start flowing in, what happens if there is a long pause (i.e. 15 seconds) in the source application before creating the log that the Universal forwarder reads.&lt;/P&gt;

&lt;P&gt;For example, something like this (time in first column is added by me to show when the line happened):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;10:00:00 Log first line
10:00:00 Log second line (same event)
10:00:18 Log third line (same event, but the app logged this 18 sec later)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How long does Splunk wait to concatenate lines into single events?&lt;/P&gt;</description>
    <pubDate>Mon, 14 May 2012 11:39:05 GMT</pubDate>
    <dc:creator>bojanz</dc:creator>
    <dc:date>2012-05-14T11:39:05Z</dc:date>
    <item>
      <title>Linemerging timer?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51119#M43867</link>
      <description>&lt;P&gt;Does Splunk have an internal timer when doing line merging?&lt;/P&gt;

&lt;P&gt;For example, if I'm doing line merging (SHOULD_LINEMERGE=true) with correct date parsing field, and events start flowing in, what happens if there is a long pause (i.e. 15 seconds) in the source application before creating the log that the Universal forwarder reads.&lt;/P&gt;

&lt;P&gt;For example, something like this (time in first column is added by me to show when the line happened):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;10:00:00 Log first line
10:00:00 Log second line (same event)
10:00:18 Log third line (same event, but the app logged this 18 sec later)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How long does Splunk wait to concatenate lines into single events?&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 11:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51119#M43867</guid>
      <dc:creator>bojanz</dc:creator>
      <dc:date>2012-05-14T11:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Linemerging timer?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51120#M43868</link>
      <description>&lt;P&gt;This might be a useful setting for you in this case.&lt;/P&gt;

&lt;P&gt;Inputs.conf.spec:&lt;/P&gt;

&lt;P&gt;time_before_close = &lt;INTEGER&gt;&lt;BR /&gt;
* Modtime delta required before Splunk can close a file on EOF.&lt;BR /&gt;
* Tells the system not to close files that have been updated in past &lt;INTEGER&gt; seconds.&lt;BR /&gt;
* Defaults to 3&lt;/INTEGER&gt;&lt;/INTEGER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:49:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51120#M43868</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2020-09-28T11:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Linemerging timer?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51121#M43869</link>
      <description>&lt;P&gt;Looks interesting, I'll test it and report back &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 15:57:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Linemerging-timer/m-p/51121#M43869</guid>
      <dc:creator>bojanz</dc:creator>
      <dc:date>2012-05-14T15:57:43Z</dc:date>
    </item>
  </channel>
</rss>

