Splunk Search

What is the different between line exist in file and events of Splunk?

indeed_2000
Motivator

Hi

I've index a 12MB file in splunk but have different between line of file and event of splunk

 

file = 114,475          lines

splunk = 104,475   events

 

file lines like this:

123456789|0123456789|0123456789|Tobe                             |Alex                            |

 

 

any idea?

Thanks

Labels (3)
Tags (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Also, check for blank lines.

Where did the line count for the file come from? Is it counting long lines as two (or more lines)?

0 Karma

indeed_2000
Motivator

@ITWhisperer 
1- there are no blank line in file.

2-vi in linux show line numbers.

3-each line one event in splunk.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

check if in the file you have some multiline event.

If not check the correct parsing of you events.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello 

1-there is no multiline event.

2- how check correctly events parsed?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

Check (usually is possible with a quick view on events9 if there are more events containing the timestamp that usually is at the beginning of the file.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello as i write in post there is no timestamp in this file.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

check if there's a common (in format) beginning of each raw, so you can identify it there are more raws merged in the same event.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello would you please tell me an example?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...