Getting Data In

Why is my props.conf should_linemerge=false configuration being ignored for json objects?

paulelms
Explorer

Hello! Sorry for my bad english.

My props.conf file:

[testudp]
SHOULD_LINEMERGE = false

I have several json objects (each on its own line) merged into one event. Best of problem is shown in the screenshots:

  1. merged objects: http://take.ms/9q90D
  2. line breaks proof: http://take.ms/u92oi

I tried some other tweaks found here, but nothing happens. I hope very much for your help. Thanks in advance.

Sorry for passive links, limitations for new user.

1 Solution

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

View solution in original post

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

paulelms
Explorer
0 Karma

markthompson
Builder

Ok, so restart your splunk instance, and then go to New UDP input, and select from the SOURCETYPE dropdown, the testUDP sourcetype, not the source.

Hope this helps

paulelms
Explorer

Thanks Sir!!!

0 Karma

markthompson
Builder

No problem

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...