Getting Data In

Why is my props.conf should_linemerge=false configuration being ignored for json objects?

paulelms
Explorer

Hello! Sorry for my bad english.

My props.conf file:

[testudp]
SHOULD_LINEMERGE = false

I have several json objects (each on its own line) merged into one event. Best of problem is shown in the screenshots:

  1. merged objects: http://take.ms/9q90D
  2. line breaks proof: http://take.ms/u92oi

I tried some other tweaks found here, but nothing happens. I hope very much for your help. Thanks in advance.

Sorry for passive links, limitations for new user.

1 Solution

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

View solution in original post

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

paulelms
Explorer
0 Karma

markthompson
Builder

Ok, so restart your splunk instance, and then go to New UDP input, and select from the SOURCETYPE dropdown, the testUDP sourcetype, not the source.

Hope this helps

paulelms
Explorer

Thanks Sir!!!

0 Karma

markthompson
Builder

No problem

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...