Getting Data In

Apache log entries concatenated into single event

splunkus
Engager

Hi,

We have been testing Splunk processing Apache access logs that we have defined using a custom log entry to output key=value pairs. For the last month everything has been working nicely, allowing us to search based on field names and values.

For example, source_type="apachekv" field1 > 30 etc

But what we have recently noticed is that for one event in the Splunk Web UI, we are now getting 2,3 or more or more apache access lines concatenated into one single Splunk event being displayed.When I look at the raw apache logfile, each entry is on a single line and looks ok.

We are using version 4.3.3, build 128297.

Has anyone seen this before. I did see an old Changelog entry (12/5/2011) about a fix for concatenated lines in Apache.

Cheers / Frank

Tags (2)
0 Karma

Takajian
Builder

We can configure how splunk treat event break. Please refer to the link as bellow.

http://docs.splunk.com/Documentation/Splunk/latest/Data/Indexmulti-lineevents

By default, splunk break event with timestamp that splunk can recognize. The setting is "BREAK_ONLY_BEFORE_DATE = true". I do not know your apache log format, but there is possibility that splunk can not recognize timestamp of your apache log so that splunk can not break each events properly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...