Getting Data In

Why is linecount 2 when it's clearly 1?

danielbb
Motivator

For multiple sourcetypes, linecount is 2, while clearly, it should be 1. Has anybody encountered this case?

Labels (4)
Tags (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @danielbb 

Please could you share a sample event and screenshot of this so we try and repeat this issue and/or diagnose?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

danielbb
Motivator

Thank you, @livehybrid@richgalloway, I'll get screenshots but, a related question, how do I access the second line of _raw?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
In splunk _raw is only one line, but it can contains e.g. \n character.
You could see it e.g. “table _raw”

danielbb
Motivator

@isoutamo  I'm running the following - 

index = <my_index> linecount=2
| table _raw 

and everything shows up as one line, I don't see any sign of \n, what do I miss? 

I also checked with an encoding tool and it doesn't show either the 13 ascii code or the 10 one within these lines. 

My biggest confusion is the fact that for this sourcetype I have -  

SHOULD_LINEMERGE=FALSE

And therefore, how come, sometimes the events have multiple lines? 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hoe you have defined line breaking?

danielbb
Motivator

I came across an identical thread at Re: How does Splunk calculate linecount? - Splunk Community

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @danielbb 

It could be something like a field extraction happening after the line breaking which is causing this, or something else. Without access to your instance we could do with seeing some sample logs along with a btool output ($SPLUNK_HOME/bin/splunk btool props list <sourceTypeName>) for your event's sourcetype. 

The thread you posted from 2013 looks like could have been related to the events having a line-break in.

Please let us know if you're able to provide a sample + props output. 

Thanks

richgalloway
SplunkTrust
SplunkTrust

Example?  Screenshot?

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...