All Apps and Add-ons

Why is the JMS Messaging Modular Input removing line breaks from events in queue?

kurtzschmitt
Engager

The data is going into an existing tool that is able to handle line breaks properly (see screenshot #1). When the JMS Messaging Modular Input pulls the data into Splunk, the events show up with all the data run together, with no line breaks (see screenshot #2). We checked to make sure it’s nothing being done via props/transforms, and the sender of the data to the queue has confirmed he’s not manipulating it on his side. I assume that means it must be something done via the JMS classes or other config files.

Any ideas as to why the line breaks are being removed?

SS#1:
alt text

SS#2:
alt text

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Uncheck the strip newline characters from message body option.

alt text

View solution in original post

Damien_Dallimor
Ultra Champion

Uncheck the strip newline characters from message body option.

alt text

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...