Splunk Cloud Platform

Splunk WSDL

PATAN
Observer

My Source is python. In WSDL I have 20 items . While am executing the query in splunk . I am getting all 20 items coming in single event. Though unable to extract the fields and show it's count. How can i get all 20 items into individual events. How can i achieve it. 

 

Thanks 

Labels (1)
Tags (1)
0 Karma

marnall
Motivator

You would have to tell Splunk how to split the events. You can do this by setting the LINE_BREAKER field in a props.conf file in an app in your indexers.

If you could post a sample of your event (with sensitive data removed) and a rough description of your splunk setup (single machine or distributed?), then it would be easier to give you more specific pointers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...