I would like to upload a text file containing more than 1500 lines without any line breaks. How do I do this in Splunk?
Here is my props.conf
[sourcetype] MAX_EVENTS = 2000 TRUNCATE = 99999 SHOULD_LINEMERGE = TRUE DATETIME_CONFIG = CURRENT
Even after making these changes, I am unable to get the data properly indexed in Splunk. I am getting line breaks. How do I properly get the events properly indexed to get the entire 1500 + lines as one event?
Please let me know.
Try this. (props.conf on Indexer/Heavy Forwarder)
[sourcetype] BREAK_ONLY_BEFORE = ^JUNKCHAR DATETIME_CONFIG = CURRENT MAX_EVENTS = 2000 NO_BINARY_CHECK = 1 SHOULD_LINEMERGE = true TRUNCATE = 99999
I have this conf and it worked for me.
SHOULDLINEMERGE = true
BREAKONLYBEFORE = (ADFASDFA)
NOBINARYCHECK = true
MAXEVENT = 2000
isvalid = true
disabled = false
pulldown_type = true
Maybe there are something that you just don't need.