I am using Splunk DB Connect to input data to an index in splunk.
I have the raw data below that I can obtain after configuring the Input from the DB Connect app.
I have a problem though with my mysql database column called "rate" where i can have multiple lines.
- Key-Value based
- Multiline Key-Value based
In the first option, my result was to have events for each line in this column, and for the second format using multiline, I have only the first line for this value: Rate=Increment: 60 s