The data is going into an existing tool that is able to handle line breaks properly (see screenshot #1). When the JMS Messaging Modular Input pulls the data into Splunk, the events show up with all the data run together, with no line breaks (see screenshot #2). We checked to make sure it’s nothing being done via props/transforms, and the sender of the data to the queue has confirmed he’s not manipulating it on his side. I assume that means it must be something done via the JMS classes or other config files.
Any ideas as to why the line breaks are being removed?
SS#1:
SS#2: