Getting Data In

Forwarders windwos log

Engager

I have a windows log forwarded to the splunk via Forwarders, and I want Forwarder to read to the splunk line by line. What should I do?

The following is my log format:
xxx.log
xxxxxxxxxxxx
xxxxxxxxxxxx
xxxxxxxxxxxx

There is only one line of text per line, no timestamp

0 Karma

Champion

I think that it can be read with the default setting.

If the character code is other than UTF - 8, please set it in props.conf.

<Configure event line breaking> line breaking⇒CRLF
http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/Configureeventlinebreaking

<How timestamp assignment works> timestamp⇒Current time
http://docs.splunk.com/Documentation/Splunk/6.6.1/Data/HowSplunkextractstimestamps

0 Karma

Engager

Thanks, Can you give me props.conf standard configuration, I do not take effect in accordance with the document profile。
My props.conf file location is located in etc/apps/search/default/props.conf

[source::D:\test*.log]
LINEBREAKERLOOKBEHIND=100
BARAKONLYBEFOREDATE = False
MAX
EVENTS = 1

0 Karma