<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does Splunk log multiple lines as a single event? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636598#M221087</link>
    <description>&lt;P&gt;I am facing an issue in which Splunk logs multiple lines as a single event- The timestamp seems to be different,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached logs for the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;21:20:14,817 INFO  [exec-68932] Interceptor.setParameters(Interceptor.java:223) - set setParameters to decode access token and id token 
21:20:14,817 INFO  [exec-68932] Interceptor.setParameters(Interceptor.java:253) - cached id 
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:95) - Get Customer id 
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:107) - User obtained
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:113) - Get flag 
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:114) - method=GET:type=Start
21:20:14,820 INFO  [exec-68932] getService(userService.java:269) - turnOn Variable
21:20:14,836 INFO  [exec-68948] Interceptor.preHandle(Interceptor.java:71) - Entered Prehandle - Interceptor 
21:20:14,836 INFO  [exec-68948] Interceptor.getCode(Interceptor.java:183) - Constructed url 
21:20:14,849 INFO  [exec-68932] callPost(RestClientUtil.java:104) - callPost(): Excecution Time=28 ms
21:20:14,850 INFO  [exec-68932] getPropertiesService(userService.java:217) - get uiflag
21:20:14,850 INFO  [exec-68932] getPropertiesService(userService.java:220) - getService(): Excecution Time=29 ms
21:20:14,850 INFO  [exec-68932] getService(userService.java:280) - success from service
21:20:14,850 INFO  [exec-68932] getService(userService.java:427) - Ui flag:O
21:20:14,851 INFO  [exec-68932] getService(userService.java:428) - FlagActivate:true 
21:20:14,851 INFO  [exec-68932] getService(userService.java:512) - true:false
21:20:14,851 INFO  [exec-68932] getService(userService.java:548) - email address:
21:20:14,851 INFO  [exec-68932] preferences(Controller.java:127) - method=GET:elapsed=31ms:type=End
21:20:14,851 INFO  [exec-68932] preferences(Controller.java:135) - Redirect url --- 
21:20:14,915 INFO  [exec-68950] Interceptor.preHandle(Interceptor.java:71) - Entered - Interceptor 
21:20:14,916 INFO  [exec-68943] Interceptor.preHandle(Interceptor.java:71) - Entered - Interceptor 
21:20:14,916 INFO  [exec-68943] Interceptor.getCode(Interceptor.java:183) - Constructed url
21:20:15,123 INFO  [exec-68948] Interceptor.setParameters(Interceptor.java:223) - set setParameters to decode access token and id token 
21:20:15,124 INFO  [exec-68948] Interceptor.setParameters(Interceptor.java:253) - cached id
21:20:15,125 INFO  [exec-68948] preferences(Controller.java:95) - Get Customer id &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Neenu&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 07:45:27 GMT</pubDate>
    <dc:creator>neenu-chandran</dc:creator>
    <dc:date>2023-03-30T07:45:27Z</dc:date>
    <item>
      <title>Why does Splunk log multiple lines as a single event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636598#M221087</link>
      <description>&lt;P&gt;I am facing an issue in which Splunk logs multiple lines as a single event- The timestamp seems to be different,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached logs for the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;21:20:14,817 INFO  [exec-68932] Interceptor.setParameters(Interceptor.java:223) - set setParameters to decode access token and id token 
21:20:14,817 INFO  [exec-68932] Interceptor.setParameters(Interceptor.java:253) - cached id 
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:95) - Get Customer id 
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:107) - User obtained
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:113) - Get flag 
21:20:14,820 INFO  [exec-68932] preferences(Controller.java:114) - method=GET:type=Start
21:20:14,820 INFO  [exec-68932] getService(userService.java:269) - turnOn Variable
21:20:14,836 INFO  [exec-68948] Interceptor.preHandle(Interceptor.java:71) - Entered Prehandle - Interceptor 
21:20:14,836 INFO  [exec-68948] Interceptor.getCode(Interceptor.java:183) - Constructed url 
21:20:14,849 INFO  [exec-68932] callPost(RestClientUtil.java:104) - callPost(): Excecution Time=28 ms
21:20:14,850 INFO  [exec-68932] getPropertiesService(userService.java:217) - get uiflag
21:20:14,850 INFO  [exec-68932] getPropertiesService(userService.java:220) - getService(): Excecution Time=29 ms
21:20:14,850 INFO  [exec-68932] getService(userService.java:280) - success from service
21:20:14,850 INFO  [exec-68932] getService(userService.java:427) - Ui flag:O
21:20:14,851 INFO  [exec-68932] getService(userService.java:428) - FlagActivate:true 
21:20:14,851 INFO  [exec-68932] getService(userService.java:512) - true:false
21:20:14,851 INFO  [exec-68932] getService(userService.java:548) - email address:
21:20:14,851 INFO  [exec-68932] preferences(Controller.java:127) - method=GET:elapsed=31ms:type=End
21:20:14,851 INFO  [exec-68932] preferences(Controller.java:135) - Redirect url --- 
21:20:14,915 INFO  [exec-68950] Interceptor.preHandle(Interceptor.java:71) - Entered - Interceptor 
21:20:14,916 INFO  [exec-68943] Interceptor.preHandle(Interceptor.java:71) - Entered - Interceptor 
21:20:14,916 INFO  [exec-68943] Interceptor.getCode(Interceptor.java:183) - Constructed url
21:20:15,123 INFO  [exec-68948] Interceptor.setParameters(Interceptor.java:223) - set setParameters to decode access token and id token 
21:20:15,124 INFO  [exec-68948] Interceptor.setParameters(Interceptor.java:253) - cached id
21:20:15,125 INFO  [exec-68948] preferences(Controller.java:95) - Get Customer id &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Neenu&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 07:45:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636598#M221087</guid>
      <dc:creator>neenu-chandran</dc:creator>
      <dc:date>2023-03-30T07:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs multiple lines as a single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636609#M221091</link>
      <description>&lt;P&gt;Hi Neenu.. Please update us the inputs.conf for this file..&lt;/P&gt;&lt;P&gt;is this happening only for a particular UF / log / source... is this a new Splunk deployment or long existing one..&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 01:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636609#M221091</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-03-30T01:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk logs multiple lines as a single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636715#M221121</link>
      <description>&lt;P&gt;this was a long exisitng one, and this happens for a specific log file&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 13:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-Splunk-log-multiple-lines-as-a-single-event/m-p/636715#M221121</guid>
      <dc:creator>neenu-chandran</dc:creator>
      <dc:date>2023-03-30T13:59:44Z</dc:date>
    </item>
  </channel>
</rss>

