The props.conf file is missing some important settings. Splunk recommends all sourcetypes have at least these 8 settings: LINE_BREAKER, TIME_PREFIX, TIME_FORMAT, MAX_TIMESTAMP_LOOKAHEAD, TRUNCATE, SHOULD_LINEMERGE, EVENT_BREAKER, and EVENT_BREAKER_ENABLE. The last two are only used by Universal Forwarders, but can be specified anywhere. I recommend these settings: sourcetype = job_logs
[source::*\trace*.txt]
TIME_PREFIX = \)
TIME_FORMAT = %d-%m-%y %H:%M:%S
MAX_TIMESTAMP_LOOKAHEAD = 18
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TRUNCATE = 10000
EVENT_BREAKER = ([\r\n]+)
EVENT_BREAKER_ENABLE = true
TRANSFORMS-set= setnull,setparsing
... View more