Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How to edit my sourcetype in props.conf to prevent Splunk from splitting events at every timestamp?

$
0
0
I've got my props.conf set up for reading entire files as one event as such: [sourcetypename] SHOULD_LINEMERGE = false LINE_BREAKER = ((*FAIL)) TRUNCATE = 999999999 MAX_EVENTS = 999999999 The file I am reading has multiple timestamps in it, and Splunk will split it into multiple events at every timestamp. How can I prevent the events from splitting at every timestamp?

Viewing all articles
Browse latest Browse all 1485

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>