Hi Guys
We find some small subsets of the logs, around 0.1% to be multiline events.
As an example, the one below. When doing a search index=symantec linecount>1 is when we see those events and the very strange dates which on some events is 1979 and 1980 as well.
I configured this in props.conf on the symantec TA on the indexers for LINE BREAKING: ([\n\r]+)\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2} , but still I see linecount>2 not more than 1
2016-05-18 01:23:30,Info,XXXXXXXXX,Category: 2,LiveUpdate Manager,A LiveUpdate session ran successfully. No new updates were available.
2262-04-02 01:24:55,Info,XXXXXXXXX,Category: 2,Symantec AntiVirus,Symantec Endpoint Protection services failed to start. (2000005F)
2262-04-02 01:24:55,Info,XXXXXXX,Category: 2,Symantec AntiVirus,Could not start Service Engine err=2000005F
... View more