Also, check for blank lines.
Where did the line count for the file come from? Is it counting long lines as two (or more lines)?
@ITWhisperer
1- there are no blank line in file.
2-vi in linux show line numbers.
3-each line one event in splunk.
Hi @indeed_2000,
check if in the file you have some multiline event.
If not check the correct parsing of you events.
Ciao.
Giuseppe
Hi @indeed_2000,
Check (usually is possible with a quick view on events9 if there are more events containing the timestamp that usually is at the beginning of the file.
Ciao.
Giuseppe
@gcusello as i write in post there is no timestamp in this file.
Hi @indeed_2000,
check if there's a common (in format) beginning of each raw, so you can identify it there are more raws merged in the same event.
Ciao.
Giuseppe
@gcusello would you please tell me an example?