Getting Data In

Web Logs Not Breaking Correctly

hartfoml
Motivator

I pointed my UF at the web log folder and there are many logs in the folder.

Then the UF started reading the *.log files the contents of the log files started coming in as one event per log file rather than breaking on each line.

How to i get the logs to break on each line in the log rather than collect the hole file as one event.

the UF is sending data to a Intermediate forwarder before going to the indexers. Should I put the linbreaking on the UF or IF

What should the breaking look like these are standered IIS log files that start with these three lines at the top of each file

`

Software: Microsoft Internet Information Services 6.0 #Version: 1.0

Date: 2007-01-29 21:02:57

Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes cs-bytes time-taken`

Is there a way to delete and re-index all the files that have been indexed already?

Tags (2)
0 Karma
1 Solution

hartfoml
Motivator

I added these lines to the $SPLUNK_HOME/etc/system/local/props.conf file and that fixed the braking

[iis]
pulldown_type = true
MAX_TIMESTAMP_LOOKAHEAD = 32
SHOULD_LINEMERGE = False
CHECK_FOR_HEADER = true

I got this from this answer How to extract fields from IIS default log file format ...

View solution in original post

0 Karma

hartfoml
Motivator

I added these lines to the $SPLUNK_HOME/etc/system/local/props.conf file and that fixed the braking

[iis]
pulldown_type = true
MAX_TIMESTAMP_LOOKAHEAD = 32
SHOULD_LINEMERGE = False
CHECK_FOR_HEADER = true

I got this from this answer How to extract fields from IIS default log file format ...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...