We recently setup a new Splunk system and were in the process of migrating some existing DBX based database inputs over to the new system when we found that the new platform is now treating the entire result set of the query as a single item when indexing the data, instead of treating every record in the result set as a separate indexed item.
Is there a configuration file that needs to be edited to rectify this, as we're copying the available settings in the actual DBX db input screen exactly.
Any help would be appreciated.
Try doing the troubleshooting steps here: http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Troubleshoot#Issues_with_bad_line_breaking...