Getting Data In

line breaker event breaker

ryanaa
Explorer

當我在SH設置好props.conf後去看我的uf端並重啟就會出現以下錯誤:

Checking conf files for problems...
Invalid key in stanza [web:access] in /opt/splunkforwarder/etc/apps/dynasafe_course_demo_ta/local/props.conf, line 3: ENVENT_BREAKER (value: ([\r\n]+)).
Invalid key in stanza [web:secure] in /opt/splunkforwarder/etc/apps/dynasafe_course_demo_ta/local/props.conf, line 6: ENVENT_BREAKER (value: ([\r\n]+)).
Your indexes and inputs configurations are not internally consistent.
這是怎麼回事

Labels (2)
Tags (1)
0 Karma
1 Solution

kiran_panchavat
SplunkTrust
SplunkTrust
@ryanaa Line breaking is not possible with the universal forwarder.  The indexer or HF is responsible for that.
The EVENT_BREAKER setting is the only one that functions with UF; nevertheless, it simply instructs UF to identify the boundaries of events and causes it to deliver whole events to indexers.
 
Try to apply this settings on an heavy forwarder or indexer.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.



Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

View solution in original post

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust
@ryanaa Line breaking is not possible with the universal forwarder.  The indexer or HF is responsible for that.
The EVENT_BREAKER setting is the only one that functions with UF; nevertheless, it simply instructs UF to identify the boundaries of events and causes it to deliver whole events to indexers.
 
Try to apply this settings on an heavy forwarder or indexer.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.



Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...