Hello,
some events are not parsed correctly and not splitted only when there is timestamp especially with "slow" events.
Solution applied from support KB https://splunk.my.site.com/customer/s/article/Multi-line-Breaking-Is-not-Working-after-Setting-up-th...
Indexers side
props.conf
[mysourcetype]
MAX_TIMESTAMP_LOOKAHEAD = 21
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S
SHOULD_LINEMERGE = true
NO_BINARY_CHECK = true
UF side
inputs.conf
# line merge
time_before_close = 60
multiline_event_extra_waittime = true
Solution applied from support KB https://splunk.my.site.com/customer/s/article/Multi-line-Breaking-Is-not-Working-after-Setting-up-th...
Indexers side
props.conf
[mysourcetype]
MAX_TIMESTAMP_LOOKAHEAD = 21
TIME_PREFIX = ^
TIME_FORMAT = %Y-%m-%d %H:%M:%S
SHOULD_LINEMERGE = true
NO_BINARY_CHECK = true
UF side
inputs.conf
# line merge
time_before_close = 60
multiline_event_extra_waittime = true