Getting Data In

Hunk Line Break Configuration

Matthias_BY
Communicator

Hello,

as i did understand within Hunk data is returned in Jason format. I have log data in my Hadoop Environment. Connection + Search is working fine.

But the line break does not work properly. In one "Hunk" Event are always 4 of my Events. Even the events have quite similar structure...

how can i configure the event break settings within Hunk? couldn't find anything in the documentation.

Thanks a lot
Matthias

Tags (2)
0 Karma
1 Solution

bwooden
Splunk Employee
Splunk Employee
When a report-generating search is initiated, Hunk uses the Hadoop MapReduce framework to process the data in place. All of the parsing of data, including source typing, event breaking, and time stamping that is normally done at index time is performed in Hadoop at search time.

source: HUNK Docs

So you can use props and transforms as you normally would -- they're just executed at search time vs. index time for HUNK.

View solution in original post

bwooden
Splunk Employee
Splunk Employee
When a report-generating search is initiated, Hunk uses the Hadoop MapReduce framework to process the data in place. All of the parsing of data, including source typing, event breaking, and time stamping that is normally done at index time is performed in Hadoop at search time.

source: HUNK Docs

So you can use props and transforms as you normally would -- they're just executed at search time vs. index time for HUNK.

Matthias_BY
Communicator

Thanks a lot. the trick was to edit the props.conf and reference the sourcetype with the file path in the stanca.

http://docs.splunk.com/Documentation/Hunk/latest/Hunk/Setupavirtualindex#Edit_props.conf_.28optional...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...