i have the lea-loggrabber.sh script working well and reliably getting all new logs from checkpoint cma into splunk. I am starting to notice that about 10 messages per 24 hours are not breaking correctly. They end up being around 257 lines long before the event breaks.
how can i force the events to be broken reliably when imported by the lea-loggrabber.sh?
all events start with loc= and should end with \r\n
I have the sourcetype set in inputs.conf where the script is called