Splunk Search
Highlighted

Splunk not displaying log data

Builder

My log file contain a long line (35000 chars) with continuous spaces [more then 60 spaces] multiple times inside the log - I can't see this log information in Splunk.

I can't change the log because its coming from 3rd party tool

Any Idea?

Tags (2)
Highlighted

Re: Splunk not displaying log data

Builder

one option is I can split this line in multiple line based on the number of spaces.

0 Karma
Highlighted

Re: Splunk not displaying log data

Legend

Do you not see the line at all in Splunk, or do you see a truncated version of it?

0 Karma
Highlighted

Re: Splunk not displaying log data

Builder

I can't see log data at all in Splunk.

I think Splunk ignoring data in a line if detect some continuous spaces - I don't know whether its true or not, its just my guess.

0 Karma
Highlighted

Re: Splunk not displaying log data

Champion

Have you verified that it has read the file correctly or checked for any errors in the internal logs?

0 Karma
Highlighted

Re: Splunk not displaying log data

Builder

Yes I verified - my log line contains 15 tab char continuously 9-10 times.

due to some privacy reason I can't post entire line here.

0 Karma
Highlighted

Re: Splunk not displaying log data

Champion

How did you verify that Splunk has read the file correctly?

0 Karma
Highlighted

Re: Splunk not displaying log data

Builder

I can see the data after this line in splunk search

0 Karma
Highlighted

Re: Splunk not displaying log data

Builder

is this bug in Splunk?

0 Karma
Highlighted

Re: Splunk not displaying log data

Champion

Could you post some example data with the secret parts hashed out or obscured?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.