Getting Data In

How to break event logs

rahulmanthena
Loves-to-Learn

In our Splunk enterprise event logs are not breaking.

Two events are coming as one event.

0 Karma

somesoni2
Revered Legend

It happens when your log data is not able to parsed correctly by Splunk automatically (if you don't have to event breaking rules defined for the sourcetype you're using and your data format is not following default Splunk's rules) OR your log data format is different from the rules you've defined for your custom sourcetype. Check what sourcetype you're using, if you've event breaking defined for that sourcetype and if log data is following that event breaking rule.

0 Karma

Sukisen1981
Champion

hi @rahulmanthena

well this is a generic question. but there are multiple options available - https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Configureeventlinebreaking

If you are struggling with something specific, please post the issue in more detauls

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...