Getting Data In

How to break event logs

rahulmanthena
Loves-to-Learn

In our Splunk enterprise event logs are not breaking.

Two events are coming as one event.

0 Karma

somesoni2
Revered Legend

It happens when your log data is not able to parsed correctly by Splunk automatically (if you don't have to event breaking rules defined for the sourcetype you're using and your data format is not following default Splunk's rules) OR your log data format is different from the rules you've defined for your custom sourcetype. Check what sourcetype you're using, if you've event breaking defined for that sourcetype and if log data is following that event breaking rule.

0 Karma

Sukisen1981
Champion

hi @rahulmanthena

well this is a generic question. but there are multiple options available - https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Configureeventlinebreaking

If you are struggling with something specific, please post the issue in more detauls

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...