Getting Data In

How to upload and index a text file containing more than 1500 lines without any line breaks?

mmohiuddin
Path Finder

Hi

I would like to upload a text file containing more than 1500 lines without any line breaks. How do I do this in Splunk?

Here is my props.conf

[sourcetype]
MAX_EVENTS = 2000
TRUNCATE = 99999
SHOULD_LINEMERGE = TRUE
DATETIME_CONFIG = CURRENT

Even after making these changes, I am unable to get the data properly indexed in Splunk. I am getting line breaks. How do I properly get the events properly indexed to get the entire 1500 + lines as one event?

Please let me know.

Thanks

somesoni2
Revered Legend

Try this. (props.conf on Indexer/Heavy Forwarder)

[sourcetype]
BREAK_ONLY_BEFORE = ^JUNKCHAR
DATETIME_CONFIG = CURRENT
MAX_EVENTS = 2000
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = true
TRUNCATE = 99999
0 Karma

mmohiuddin
Path Finder

Still I get only 704 lines indexed out of total of 1503 lines after applying the new props.conf on Indexer

0 Karma

edrivera3
Builder

I have this conf and it worked for me.

SHOULD_LINEMERGE = true
BREAK__ONLY_BEFORE = (ADFASDFA)
NO_BINARY_CHECK = true
MAX_EVENT = 2000
is_valid = true
disabled = false
pulldown_type = true

Maybe there are something that you just don't need.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...