Getting Data In

Scripted Input Multiline Event wanted

hypePG
Path Finder

Hey,

I got a script which is executing a vmstat command on a host. Since yesterday I received the output in a single multiline event:

memTotalMB   memFreeMB   memUsedMB  memFreePct  memUsedPct   pgPageOut  swapUsedPct   pgSwapOut   cSwitches  interrupts       forks   processes     threads  loadAvg1mi  waitThreads    interrupts_PS    pgPageIn_PS    pgPageOut_PS
     50284       11822       38461        23.5        76.5  8730068031         25.6    23270004  2386506467  3085994601    95621910         274     1779        1.38        0.00      
2586.57         72.36        520.60

Since a few days the data is coming in in two parts. Header and Data like this:

    1   2/19/18
10:48:44.000 AM 
     50284       14795       35489        29.4        70.6  9031516273         34.8    24020729  4048038777   392164802    98916588         276        1813        1.51        0.00       4607.00         54.55       1477.27

    2   2/19/18
10:48:44.000 AM 
memTotalMB   memFreeMB   memUsedMB  memFreePct  memUsedPct   pgPageOut  swapUsedPct   pgSwapOut   cSwitches  interrupts       forks   processes     threads  loadAvg1mi  waitThreads    interrupts_PS    pgPageIn_PS    pgPageOut_PS

I didn't change any configuration at all. In the second case I can't use the multikv command becuase the headers for the fields are missing.

How can I fix this?

Regards,

Max

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

Hi

you probably need to configure EVENT BREAKER to avoid breaking your event in pieces before getting to indexers

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...