All Apps and Add-ons

How do I configure Ironstream and/or Splunk to treat events individually, rather than aggregating events by seconds?

kcarlin0407
New Member

How do I configure Ironstream and/or Splunk to treat events individually, rather than aggregating events by time?
I'm sending many events per second to Splunk via Ironstream, and often there are 3 or more events getting indexed as one event.

Tags (1)
0 Karma

jeastman
Path Finder

I always tell our customers to use the following parameters in their props.conf file for sourcetype=syncsortMF

SHOULD_LINEMERGE = false
LINE_BREAKER = \"}$

0 Karma

lguinn2
Legend

You probably need to set the line-breaking rules for the data in props.conf
If each event is a single line, the only setting that you probably need is

SHOULD_LINEMERGE = false

For more detailed help from the Answers community, we need to see a sample of the data stream (obfuscated of course).

You can also read more about this in the documentation: Configure event line breaking

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...