Getting Data In

line breaker event breaker

ryanaa
Explorer

當我在SH設置好props.conf後去看我的uf端並重啟就會出現以下錯誤:

Checking conf files for problems...
Invalid key in stanza [web:access] in /opt/splunkforwarder/etc/apps/dynasafe_course_demo_ta/local/props.conf, line 3: ENVENT_BREAKER (value: ([\r\n]+)).
Invalid key in stanza [web:secure] in /opt/splunkforwarder/etc/apps/dynasafe_course_demo_ta/local/props.conf, line 6: ENVENT_BREAKER (value: ([\r\n]+)).
Your indexes and inputs configurations are not internally consistent.
這是怎麼回事

Labels (2)
Tags (1)
0 Karma
1 Solution

kiran_panchavat
SplunkTrust
SplunkTrust
@ryanaa Line breaking is not possible with the universal forwarder.  The indexer or HF is responsible for that.
The EVENT_BREAKER setting is the only one that functions with UF; nevertheless, it simply instructs UF to identify the boundaries of events and causes it to deliver whole events to indexers.
 
Try to apply this settings on an heavy forwarder or indexer.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.



Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

View solution in original post

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust
@ryanaa Line breaking is not possible with the universal forwarder.  The indexer or HF is responsible for that.
The EVENT_BREAKER setting is the only one that functions with UF; nevertheless, it simply instructs UF to identify the boundaries of events and causes it to deliver whole events to indexers.
 
Try to apply this settings on an heavy forwarder or indexer.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.



Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...