Getting Data In

how can I force splunk read file line by line

Communicator

I have a big file about 17G,when I input it as a file,splunk treat some record as multi-line.
The file is UTF-8 Unicode text.
how can I force splunk read file line by line ?
Thank you very much!

Tags (2)
0 Karma
1 Solution

Builder

You need to configure props.conf in order to force splunk index data with single line.
The configuration will be following.

[yoursourcetype]
SHOULD
LINEMERGE = false

You can also refer to the manual as bellow.

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Indexmulti-lineevents

View solution in original post

Communicator

it works!
Thank you !
the manual are powerful!

0 Karma

Builder

You need to configure props.conf in order to force splunk index data with single line.
The configuration will be following.

[yoursourcetype]
SHOULD
LINEMERGE = false

You can also refer to the manual as bellow.

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Indexmulti-lineevents

View solution in original post