Getting Data In

Why is multiline single event with sourcetype nginx:plus:kv intermittently showing?

rasikmhetre
Explorer

I am using the nginx app to ship nginx logs to Splunk, everything works well but intermittently I see a single event consisting of multiple nginx access loglines. 

Nginx app itself has an EventBreaker=enabled and Eventbreaker=regex. (This doesn't work 10-20% of the time).

Can someone please help or am I missing something?

My inputs.conf :

[monitor:///var/log/nginx-access.log]
index = artifactory
disabled = false
source = nginx-access
sourcetype = nginx:plus:kv

[monitor:///var/log/nginx-error.log]
disabled = false
sourcetype = nginx:plus:error
index = artifactory
source = nginx-error.

Nginx app has already created props.conf at Search head cluster.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rasikmhetre - Please provide log samples (mask critical values). So we can help you write proper line breaker.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...