How does Splunk calculate linecount?

Splunk Employee
Splunk Employee

I have logs that are linebreaking correctly, and are single line events, but the linecount is showing as "2".

I poked around in the original file and there seems to only be single line endings on each line (per vi :set list)

What does Splunk use to calculate linecount?


@mloven now that you work for Splunk did you get an answer? I'm seeing the same behavior

0 Karma


Also seeing the same behavior where one line events are showing up at 2. Also only seeing single line endings when checking out the log on the forwarder host

0 Karma

Path Finder

I dont know if this answers your question, but you might find your answer here..