Getting Data In

What is the search query to get the events which are having linebreaking , data parsing, timestamp configuration issue?

lksridhar
Explorer

Hi Folks,

What is the search query to get the events details which are having line breaking, data parsing and timestamp configuration issue?

0 Karma
1 Solution

adonio
Ultra Champion

Hello there,

try the following search:

index=_internal sourcetype=splunkd source=*splunkd.log (component=AggregatorMiningProcessor OR component=LineBreakingProcessor) (log_level=WARN OR log_level=ERROR)

hope it helps

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

I wrote an application to determine this issue and a variety of other scenarios, it's called Alerts For Splunk Admins .
I have an update or two coming in the next two week but your scenario is likely covered the savedsearches.conf is in github

0 Karma

adonio
Ultra Champion

Hello there,

try the following search:

index=_internal sourcetype=splunkd source=*splunkd.log (component=AggregatorMiningProcessor OR component=LineBreakingProcessor) (log_level=WARN OR log_level=ERROR)

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...