Getting Data In

Why is multiline single event with sourcetype nginx:plus:kv intermittently showing?

rasikmhetre
Explorer

I am using the nginx app to ship nginx logs to Splunk, everything works well but intermittently I see a single event consisting of multiple nginx access loglines. 

Nginx app itself has an EventBreaker=enabled and Eventbreaker=regex. (This doesn't work 10-20% of the time).

Can someone please help or am I missing something?

My inputs.conf :

[monitor:///var/log/nginx-access.log]
index = artifactory
disabled = false
source = nginx-access
sourcetype = nginx:plus:kv

[monitor:///var/log/nginx-error.log]
disabled = false
sourcetype = nginx:plus:error
index = artifactory
source = nginx-error.

Nginx app has already created props.conf at Search head cluster.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rasikmhetre - Please provide log samples (mask critical values). So we can help you write proper line breaker.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...