Greetings!
I have Splunk forwarder installed on a Bro IDS host and set all bro log files to be forwarded to a Splunk indexer. Currently I have one small issue. Sometime, when multiple smtp events are recorded at the same time in the bro smtp.log, these events are merged into one single entry when I perform search in Splunk. This also caused the field extraction to not work properly. Anyone knows how to separate the data into multiple entries?
Thanks.
hi, this is most likely a linebreak problem -- if you can post anonymized samples of it not working, we can probably get it fixed.
I've had this same problem (http://answers.splunk.com/answers/154056/why-are-bro-smtp-logs-not-breaking-into-multiple-events.htm...). I was never able to solve the problem. When looking at the raw text logs, there was nothing obviously different between events that properly split and those that did not.