I have a windows log forwarded to the splunk via Forwarders, and I want Forwarder to read to the splunk line by line. What should I do?
The following is my log format:
xxx.log
xxxxxxxxxxxx
xxxxxxxxxxxx
xxxxxxxxxxxx
There is only one line of text per line, no timestamp
I think that it can be read with the default setting.
If the character code is other than UTF - 8, please set it in props.conf.
<Configure event line breaking> line breaking⇒CRLF
http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Configureeventlinebreaking
<How timestamp assignment works> timestamp⇒Current time
http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/HowSplunkextractstimestamps
Thanks, Can you give me props.conf standard configuration, I do not take effect in accordance with the document profile。
My props.conf file location is located in etc/apps/search/default/props.conf
[source::D:\test*.log]
LINE_BREAKER_LOOKBEHIND=100
BARAK_ONLY_BEFORE_DATE = False
MAX_EVENTS = 1