Getting Data In

Single events are combined into multi-line events

frankejj
Explorer

Hello,

I have a log file that is being indexed and many of the lines show up combined into multi-line events however there seems to be no logic behind the combining. Each line has a timestamp yet they are being combined regardless. I have no props.conf in this config - therefore I assume default line merging is in effect.

Example log data:

08:26:53,465 WARN [com.sap.ca.alfresco.base.repo.importer.SapImporterBootstrap] Skiping bootstrap

08:26:53,561 WARN [com.sap.ca.alfresco.base.repo.importer.SapImporterBootstrap] Skiping bootstrap

08:26:53,699 WARN [com.sap.ca.alfresco.base.repo.importer.SapImporterBootstrap] Skiping bootstrap

08:26:53,765 WARN [com.sap.ca.alfresco.base.repo.importer.SapImporterBootstrap] Skiping bootstrap

08:26:59,234 WARN [org.alfresco.repo.cache.TransactionalCache.org.alfresco.cache.avmNodeTransactionalCache] Transactional update cache 'org.alfresco.cache.avmNodeTransactionalCache' is full (5000).

08:27:05,532 WARN [org.alfresco.repo.cache.TransactionalCache.org.alfresco.cache.contentDataTransactionalCache] Transactional update cache 'org.alfresco.cache.contentDataTransactionalCache' is full (1000).

08:27:23,223 WARN [com.sap.ca.alfresco.base.repo.importer.SapImporterBootstrap] Skiping bootstrap

08:27:23,961 WARN [com.sap.ca.alfresco.base.repo.importer.SapImporterBootstrap] Skiping bootstrap

08:27:23,962 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] Starting 'OOoDirect' subsystem, ID: [OOoDirect, default]

08:27:23,988 INFO [org.alfresco.config.FixedPropertyPlaceholderConfigurer] Loading properties file from class path resource [alfresco/version.properties]

Result

The result is some of the lines are combined to multi-line and some are not but I cannot distinguish what is causing the combining/breaking.

Question

Is it possible to configure a regex to recognize the timestamp on the new line and then use props.conf to further configure the line breaking?

Thanks,
John

Tags (1)
0 Karma
1 Solution

mw
Splunk Employee
Splunk Employee

Probably an issue with the timestamps. See if this helps:

# props.conf
[my_sourcetype]
SHOULD_LINEMERGE = false
TIME_FORMAT = %H:%M:%S,%n

View solution in original post

0 Karma

frankejj
Explorer

Thanks! Setting the time format did the trick. I did not change line merge to false because there are also many multi-line entries in these logs.

0 Karma

mw
Splunk Employee
Splunk Employee

Probably an issue with the timestamps. See if this helps:

# props.conf
[my_sourcetype]
SHOULD_LINEMERGE = false
TIME_FORMAT = %H:%M:%S,%n
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...