Hi pyro_wood,
thank you for your answer. The log files are Log4j webapp logs from a tomcat server application and the entries look like this one:
03-11 14:23:48,601 [pool-15-thread-1][] DEBUG ion.communication.AbstractHTTPRequestExecutor ( ) - Received response: HTTP/1.1 200 OK
The first time I used Splunk it worked without any problems and logging hasn't changed since then, so I can't imagine it would be a problem with line breaking.
The following picture shows the incoming log entries of the last 4 hours on the Splunk Index Server:
The gaps are up to 1 hour, in which no entries were received and should not be present since the log file is very busy and writes several log entries in every minute. But as you can see, sometimes the Indexer reseive
... View more