Getting Data In

Why is my props.conf should_linemerge=false configuration being ignored for json objects?

paulelms
Explorer

Hello! Sorry for my bad english.

My props.conf file:

[testudp]
SHOULD_LINEMERGE = false

I have several json objects (each on its own line) merged into one event. Best of problem is shown in the screenshots:

  1. merged objects: http://take.ms/9q90D
  2. line breaks proof: http://take.ms/u92oi

I tried some other tweaks found here, but nothing happens. I hope very much for your help. Thanks in advance.

Sorry for passive links, limitations for new user.

1 Solution

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

View solution in original post

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

paulelms
Explorer
0 Karma

markthompson
Builder

Ok, so restart your splunk instance, and then go to New UDP input, and select from the SOURCETYPE dropdown, the testUDP sourcetype, not the source.

Hope this helps

paulelms
Explorer

Thanks Sir!!!

0 Karma

markthompson
Builder

No problem

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...