Getting Data In

Is the regex for line break in an HF/Indexer the same as the Event_Breaker in a universal forwarder?

Path Finder

Hi All,

Could you please help me understand if the regex for line break in HF/Indexer is the same as the Event_Breaker in a universal forwarder? Also, if Event_Breaker is defined, is it still recommended to give Line Break in heavy forwarder or Indexer?

0 Karma

SplunkTrust
SplunkTrust

Yes to both questions, EVENT_BREAKER requires the EVENT_BREAKER_ENABLE flag, it helps the universal forwarder know when it can change to a new server listed in outputs.conf when the autoLBFrequency or autoLBVolume is reached, without this setting the forwarder will wait for the file that is monitored to stop updating for a period of time before making the switch to a different backend server in the outputs.conf list.

The above setting makes no difference to the indexer/heavy forwarding tier which is parsing the data (except in a few edge cases on the UF).

Therefore you want both, the LINE_BREAKER is still required if you have SHOULD_LINEMERGE=false and you want a multi-line event.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!