Splunk Search

What is the different between line exist in file and events of Splunk?

indeed_2000
Motivator

Hi

I've index a 12MB file in splunk but have different between line of file and event of splunk

 

file = 114,475          lines

splunk = 104,475   events

 

file lines like this:

123456789|0123456789|0123456789|Tobe                             |Alex                            |

 

 

any idea?

Thanks

Labels (3)
Tags (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Also, check for blank lines.

Where did the line count for the file come from? Is it counting long lines as two (or more lines)?

0 Karma

indeed_2000
Motivator

@ITWhisperer 
1- there are no blank line in file.

2-vi in linux show line numbers.

3-each line one event in splunk.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

check if in the file you have some multiline event.

If not check the correct parsing of you events.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello 

1-there is no multiline event.

2- how check correctly events parsed?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

Check (usually is possible with a quick view on events9 if there are more events containing the timestamp that usually is at the beginning of the file.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello as i write in post there is no timestamp in this file.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @indeed_2000,

check if there's a common (in format) beginning of each raw, so you can identify it there are more raws merged in the same event.

Ciao.

Giuseppe

0 Karma

indeed_2000
Motivator

@gcusello would you please tell me an example?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...