Getting Data In

Logs parses fine during the day but groups multiple entries together from midnight - 1am

Path Finder

alt text

0 Karma

SplunkTrust
SplunkTrust

Can you post your props.conf which is located on your indexer(s) under $SPLUNK_HOME/etc/system/local?

0 Karma

Path Finder

We are using the settings from the /opt/splunk/etc/system/default/props.conf

0 Karma

SplunkTrust
SplunkTrust

Did you copy and paste the default settings to your local settings?

I would recommend you create a new props.conf under $SPLUNK_HOME/etc/system/local

[source::YOUR_SOURCE_PATH]
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S,$3N
MAX_TIMESTAMP_LOOAKAHEAD = 30
LINE_BREAKER = \[\d\/\d+\/\d+\s\d\:\d+\:\d+\:\d+\sEDT\]
SHOULD_LINEMERGE = false
TRUNCATE = false
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!