Hi,
How can I merge all lines of a config file into one single event?
My inputs.conf is:
[monitor:D:\CatTools3\Config.Current.Running.ASA-CLI.txt]
sourcetype = CatTools:Firewall:ASA-CLI
host_regex = Config.Current.Running.(?P.+)
index = eli
And my props.conf is:
[CatTools:Firewall:ASA-CLI]
SHOULD_LINEMERGE = TRUE
But on Splunk search, each line is a single event, so now I have more than 5000 events instead of one event of 5000 lines.
↧