Getting Data In

Event Breaking Issue

bharathkumarnec
Contributor

Hi Everyone,

Need help regarding event breaking, below is my current scenario:

One my log file in the indexer is updating not updating the log in frequent intervals, for example:

Event starts with date in format "2015-10-01 07:31:09.733+0000" and this event will end writing data after 5min with 'n' number of lines, and next event will start with the same date format. The problem is as the log is taking 5min time to finish writing the event, splunk splitting one event into three or four different events.

Kindly help me out with this problem, let me know if more information is required.

Thanks in Advance

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

You can try using the time_before_close parameter inside inputs.conf and setting it to something like 300 but be sure to test it on one server/file first and if you decide to keep it, be sure it is only on these kinds of inputs because this will cause a 5-minute delay in getting events into Splunk.

View solution in original post

woodcock
Esteemed Legend

You can try using the time_before_close parameter inside inputs.conf and setting it to something like 300 but be sure to test it on one server/file first and if you decide to keep it, be sure it is only on these kinds of inputs because this will cause a 5-minute delay in getting events into Splunk.

bharathkumarnec
Contributor

Thanks Woodcock, for your inputs!

0 Karma

bharathkumarnec
Contributor

The usage of this parameter is working fine for me..Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...