I have a windows log forwarded to the splunk via Forwarders, and I want Forwarder to read to the splunk line by line. What should I do?
The following is my log format：
There is only one line of text per line, no timestamp
I think that it can be read with the default setting.
If the character code is other than UTF - 8, please set it in props.conf.
＜Configure event line breaking＞ line breaking⇒CRLF
＜How timestamp assignment works＞ timestamp⇒Current time
Thanks, Can you give me props.conf standard configuration, I do not take effect in accordance with the document profile。
My props.conf file location is located in etc/apps/search/default/props.conf
BARAKONLYBEFOREDATE = False
MAXEVENTS = 1