Splunk Search

how to tell if I have multiline events?

V_at_Splunk
Splunk Employee
Splunk Employee

Because wc -l of the input doesn't match my event count, and I'm trying to troubleshoot.

Tags (1)
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

You can also search: linecount!=1

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

You can also search: linecount!=1

View solution in original post

V_at_Splunk
Splunk Employee
Splunk Employee
* | stats count by linecount
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!