My logs are joining in some events and with that I'm missing values that I later adding, for splunk only counts as valid a field inside the log.
example:
*{"id":"4122257","type":"TRANSACAO_CREDITO","amount":3.73,"queued_ms":"3","paySmart_ms":"0","elapsed_ms":"311","instance":"macarico.xxx.xxxx","brand":"XXX","product":1,"status":"approved","tags":["AUTHORIZATION_REQUEST","MAGNETIC","PIN_ENTRY_CAP","PIN","CVC2","NO_CHIP_DATA","TRACK1_PRESENT","ATTENDED_TERMINAL","MERCHANT_TERMINAL_ON_LOCAL","CARDHOLDER_PRESENT","CARD_PRESENT","TERMINAL_MANUAL_MAGNETIC_CHIP","NO_CEP","NO_CNPJ"]} {"id":"4122258","type":"TRANSACAO_CREDITO","amount":20.50,"queued_ms":"2","paySmart_ms":"0","elapsed_ms":"317","instance":"macarico.xxx.xxxx","brand":"XXX","product":1,"status":"denied","reason":"NEGADA_CODIGO_DE_SEGURANCA_2_INVALIDO","tags":["AUTHORIZATION_REQUEST","MAGNETIC","PIN_ENTRY_CAP","PIN","CVC2","NO_CHIP_DATA","TRACK2_PRESENT","ATTENDED_TERMINAL","MERCHANT_TERMINAL_ON_LOCAL","CARDHOLDER_PRESENT","CARD_PRESENT","TERMINAL_MAGNETIC_CHIP","CEP","NO_CNPJ"]}
*
these two were json with the same timestamp and the same event, when they should be in two different events.
And this only occurs in some random cases.
Someone already had a similar experience?
... View more