Splunk Search

how to tell if I have multiline events?

Splunk Employee
Splunk Employee

Because wc -l of the input doesn't match my event count, and I'm trying to troubleshoot.

Tags (1)
1 Solution

Splunk Employee
Splunk Employee

You can also search: linecount!=1

View solution in original post

Splunk Employee
Splunk Employee

You can also search: linecount!=1

View solution in original post

Splunk Employee
Splunk Employee
* | stats count by linecount
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!