I have a text file that has 8824 lines. I have configured MAX_EVENT= 1000. Then, Splunk only read the file until line 7599. Why Splunk did not read my file till the end of file? Is there anything that I need to configure?
It is a health check file. This is my
BREAK_ONLY_BEFORE = CIC: Node IP Address|Service Status:|\-{10}|\={12}|Summary:|Memory Details on
Hi @Azwaliyana
try to use on your input stanza this command
crcSalt = <SOURCE>