Splunk Cloud Platform

Splunk WSDL

PATAN
Observer

My Source is python. In WSDL I have 20 items . While am executing the query in splunk . I am getting all 20 items coming in single event. Though unable to extract the fields and show it's count. How can i get all 20 items into individual events. How can i achieve it. 

 

Thanks 

Labels (1)
Tags (1)
0 Karma

marnall
Motivator

You would have to tell Splunk how to split the events. You can do this by setting the LINE_BREAKER field in a props.conf file in an app in your indexers.

If you could post a sample of your event (with sensitive data removed) and a rough description of your splunk setup (single machine or distributed?), then it would be easier to give you more specific pointers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...