Getting Data In

monitor records several lines in one _raw


I have a file with 30 lines that want to register in Splunk.
After you have configured the inputs.conf the splunk _raw saved one, with all lines of the file, when they should be 30 _raw
This is my configuration inputs.conf
I will be failing in something?

index = main 
source = txt 
host = SIEM 
SourceType = customers 
disabled = false
0 Karma

Re: monitor records several lines in one _raw


This doesn't have anything to do with what you configure in inputs.conf, rather it's related to how Splunk is breaking data into events. For more information, read here:

0 Karma