<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How come empty event information is being displayed? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418011#M120235</link>
    <description>&lt;P&gt;I understand. &lt;BR /&gt;
This data is a Apache Tomcat console log, we used Splunk to read those files&lt;BR /&gt;
As I see it, a nomal log appears like this: &lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mINFO  Log Info message&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mDEBUG  Log debug message&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mERROR  Log Error message&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mWARNING  Log Warning message&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;But I see several occurrences of, as I named it, empty log entries&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:39.157 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:38.290 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:37.455 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:36.755 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:36.389 | &amp;#27;[m&lt;/P&gt;

&lt;P&gt;I've got no idea what they could mean. I tried a local Splunk installation to read my Apache Tomcat local server and i encountered this kind on "empty log events". I would dare say it is a server issue, because we don't log subsequent empty logs in our application.&lt;/P&gt;

&lt;P&gt;I hope this helps a little. Thank you for the remark about not enough information.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Oct 2018 14:57:10 GMT</pubDate>
    <dc:creator>cschavarro</dc:creator>
    <dc:date>2018-10-08T14:57:10Z</dc:date>
    <item>
      <title>How come empty event information is being displayed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418009#M120233</link>
      <description>&lt;P&gt;I've been seeing some occurrences in Splunk that I haven't been able to find a reason why this is being shown&lt;BR /&gt;
We use splunk to read our Apache Tomcat console logs from QA and Production env.&lt;/P&gt;

&lt;P&gt;Normal log event is shown like this: &lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:30.549 | &amp;#27;[m&amp;#27;[0;32mINFO [Class] Log info message&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:30.549 | &amp;#27;[m&amp;#27;[0;32mDEBUG [Class] Log debug message&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:30.549 | &amp;#27;[m&amp;#27;[0;32mWARNING [Class] Log warning message&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:30.549 | &amp;#27;[m&amp;#27;[0;32mERROR [Class] Log error message&lt;/P&gt;

&lt;P&gt;But I have encountered, in great quantities,  this kind on log events&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/09/04 00:53:59.734 | &amp;#27;[m&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/09/04 00:54:59.734 | &amp;#27;[m&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;They look like empty log entries, but we don't log 20 empty log entries subsequently. I tried testing this in a local environment with a local splunk server and I notice this kid of message as well, but not int he same amount as in our QA or Production servers.&lt;/P&gt;

&lt;P&gt;Does anyone have an idea of what this could mean?&lt;/P&gt;

&lt;P&gt;We are using Apache Tomcat 7. (not sure about the build)&lt;/P&gt;

&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 16:24:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418009#M120233</guid>
      <dc:creator>cschavarro</dc:creator>
      <dc:date>2018-10-05T16:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: How come empty event information is being displayed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418010#M120234</link>
      <description>&lt;P&gt;you are going to have to add a &lt;STRONG&gt;LOT&lt;/STRONG&gt; more context this question if you want help...no idea what you're asking, what this data is, what you mean by empty event, etc.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2018 13:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418010#M120234</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2018-10-07T13:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: How come empty event information is being displayed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418011#M120235</link>
      <description>&lt;P&gt;I understand. &lt;BR /&gt;
This data is a Apache Tomcat console log, we used Splunk to read those files&lt;BR /&gt;
As I see it, a nomal log appears like this: &lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mINFO  Log Info message&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mDEBUG  Log debug message&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mERROR  Log Error message&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;INFO   | jvm 1    | main    | 2018/10/05 20:37:46.463 | [m[0;32mWARNING  Log Warning message&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;But I see several occurrences of, as I named it, empty log entries&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:39.157 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:38.290 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:37.455 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:36.755 | &amp;#27;[m&lt;BR /&gt;
INFO   | jvm 1    | main    | 2018/10/05 20:37:36.389 | &amp;#27;[m&lt;/P&gt;

&lt;P&gt;I've got no idea what they could mean. I tried a local Splunk installation to read my Apache Tomcat local server and i encountered this kind on "empty log events". I would dare say it is a server issue, because we don't log subsequent empty logs in our application.&lt;/P&gt;

&lt;P&gt;I hope this helps a little. Thank you for the remark about not enough information.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 14:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418011#M120235</guid>
      <dc:creator>cschavarro</dc:creator>
      <dc:date>2018-10-08T14:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: How come empty event information is being displayed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418012#M120236</link>
      <description>&lt;P&gt;Do the messages exist anywhere else in the index? In other words, if you're looking for a specific message, search for that in "All time" so you can see if it's linebreaking correctly. It could be that it is linebreaking due to the numbers later in the message. If this is the case, set up a LINE_BREAKER in props.conf on the indexers.&lt;/P&gt;

&lt;P&gt;Best idea, however, is to grab the log file and drop it into your test environment. This way you can see what's happening to the file and how it is being processed at indextime.&lt;BR /&gt;
(Launcher -&amp;gt; Add Data -&amp;gt; Upload files from my computer)&lt;BR /&gt;
&lt;A href="https://MY_TEST_SERVER:8000/en-GB/manager/search/adddata"&gt;https://MY_TEST_SERVER:8000/en-GB/manager/search/adddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 15:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418012#M120236</guid>
      <dc:creator>althomas</dc:creator>
      <dc:date>2018-10-08T15:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: How come empty event information is being displayed?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418013#M120237</link>
      <description>&lt;P&gt;I will take a look if I can get the log files. Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 16:13:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-come-empty-event-information-is-being-displayed/m-p/418013#M120237</guid>
      <dc:creator>cschavarro</dc:creator>
      <dc:date>2018-10-08T16:13:41Z</dc:date>
    </item>
  </channel>
</rss>

