Getting Data In
Highlighted

monitor records several lines in one _raw

Communicator

Hello
I have a file with 30 lines that want to register in Splunk.
After you have configured the inputs.conf the splunk _raw saved one, with all lines of the file, when they should be 30 _raw
This is my configuration inputs.conf
I will be failing in something?

[monitor:///var/log/splunk/data_clientes.log] 
index = main 
source = txt 
host = SIEM 
SourceType = customers 
disabled = false
0 Karma
Highlighted

Re: monitor records several lines in one _raw

Legend

This doesn't have anything to do with what you configure in inputs.conf, rather it's related to how Splunk is breaking data into events. For more information, read here: http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/Indexmulti-lineevents

0 Karma