Getting Data In

events print()-ed from Python input merged

gliptak
Explorer

While using print() to emit events from Python input, sometimes the events from separate print statements get merged. An example (edited) below:

 

 

2020-11-05T20:23:21.988802+00:00, application="application1"
2020-11-05T20:23:21.993878+00:00, application="application2"

 

 

I'm unclear why these particular ones got merged (there were other records print() -ed at 2020-11-05T20:23:21, and all events had increasing/unique timestamp)

Any pointers on how to prevent this? Thanks

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The example looks like two separate events.  How are they "merged"?  What are the props.conf settings for that sourcetype?

---
If this reply helps you, Karma would be appreciated.

gliptak
Explorer

events.png

sourcetype wasn't configured while above event was indexed

Configuring the sourcetype with SHOULD_LINEMERGE = false might not work well as events have multi-line fields

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...