I've seen several XML break examples, but none yet which quite matched this issue.
I have an app that writes a file per log in XML format. it begins with the xml header, <?xml and ends with </Job> and these can be very large XML logs.
My props.conf looks like this:
[DumbApp:ActLogs]
KV_MODE = xml
BREAK_ONLY_BEFPRE = (<?xml)
category = Application
description = Job Logs from DumbApp
disabled = false
MAX_EVENTS = 100000
pulldown_type = true
SHOULD_LINEMERGE = false
But for every log it breaks after <PercentComplete> and then each XML stanza in that log after that is treated as a different event. I want it not to break at all basically, and treat each log file as one solid event. Every combination of linemerge settings, or setting break_only_before to something that would encompass the whole file, beginning to end, has not worked.
I'm running splunk 6.2.3.
... View more