Splunk Search

What is the different between line exist in file and events of Splunk?

indeed_2000
Motivator

Hi

I've index a 12MB file in splunk but have different between line of file and event of splunk

 

file = 114,475          lines

splunk = 104,475   events

 

file lines like this:

123456789|0123456789|0123456789|Tobe                             |Alex                            |

 

 

any idea?

Thanks

Labels (3)
Tags (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Also, check for blank lines.

Where did the line count for the file come from? Is it counting long lines as two (or more lines)?

0 Karma

indeed_2000
Motivator

@ITWhisperer 
1- there are no blank line in file.

2-vi in linux show line numbers.

3-each line one event in splunk.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

check if in the file you have some multiline event.

If not check the correct parsing of you events.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello 

1-there is no multiline event.

2- how check correctly events parsed?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

Check (usually is possible with a quick view on events9 if there are more events containing the timestamp that usually is at the beginning of the file.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello as i write in post there is no timestamp in this file.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

check if there's a common (in format) beginning of each raw, so you can identify it there are more raws merged in the same event.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello would you please tell me an example?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...