Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

How to edit my props.conf so that each line of log file is one event?

$
0
0
I have a log file which is being sent to Splunk. When I search, I see 257 lines per 1 event and remaining lines as separate events. I tried below, however it is not working. cat ~/local/props.conf [task_breakdown] SHOULD_LINEMERGE = False LINE_BREAKER = [\n\r]+ TRUNCATE = 999999 NO_BINARY_CHECK = true

Viewing all articles
Browse latest Browse all 1485

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>