Getting Data In

How to break event logs

rahulmanthena
Loves-to-Learn

In our Splunk enterprise event logs are not breaking.

Two events are coming as one event.

0 Karma

somesoni2
Revered Legend

It happens when your log data is not able to parsed correctly by Splunk automatically (if you don't have to event breaking rules defined for the sourcetype you're using and your data format is not following default Splunk's rules) OR your log data format is different from the rules you've defined for your custom sourcetype. Check what sourcetype you're using, if you've event breaking defined for that sourcetype and if log data is following that event breaking rule.

0 Karma

Sukisen1981
Champion

hi @rahulmanthena

well this is a generic question. but there are multiple options available - https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Configureeventlinebreaking

If you are struggling with something specific, please post the issue in more detauls

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...