Getting Data In

Is it possible to ignore line breaker raw data?

vietlq414
Explorer

I'm monitor a folder with some file. Could I make whole file as one event without line_breaker? I've tried transaction by source but it does not working as well as I want.

0 Karma

outis
New Member

alt text

When you monitor, choose Event Breaks>Regex and type ([\r].*)
Hope that it can help you!

0 Karma

vietlq414
Explorer

my file has more than 100000 line. i've try and add TRUNCATE properties but it did not work.

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...