Getting Data In

Is the regex for line break in an HF/Indexer the same as the Event_Breaker in a universal forwarder?

akshatj2
Path Finder

Hi All,

Could you please help me understand if the regex for line break in HF/Indexer is the same as the Event_Breaker in a universal forwarder? Also, if Event_Breaker is defined, is it still recommended to give Line Break in heavy forwarder or Indexer?

0 Karma

gjanders
SplunkTrust
SplunkTrust

Yes to both questions, EVENT_BREAKER requires the EVENT_BREAKER_ENABLE flag, it helps the universal forwarder know when it can change to a new server listed in outputs.conf when the autoLBFrequency or autoLBVolume is reached, without this setting the forwarder will wait for the file that is monitored to stop updating for a period of time before making the switch to a different backend server in the outputs.conf list.

The above setting makes no difference to the indexer/heavy forwarding tier which is parsing the data (except in a few edge cases on the UF).

Therefore you want both, the LINE_BREAKER is still required if you have SHOULD_LINEMERGE=false and you want a multi-line event.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...