Getting Data In

Event Breaks at line 257

jpraman2000
New Member

Events always breaks at line 257. I have made changes to props.conf file under system/local in forwarder. But for some reason it is not working. Below are the props.conf settings

[source]
MAX_EVENTS = 5000
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE_DATE = True

Tags (1)
0 Karma

linu1988
Champion

Hello,
It is not a heavy forwarder, you need t place the props.conf file in indexer. If data already indexed. Please delete them and re-index to fid the desired result.

Thanks

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...