Getting Data In

Why is my props.conf should_linemerge=false configuration being ignored for json objects?

paulelms
Explorer

Hello! Sorry for my bad english.

My props.conf file:

[testudp]
SHOULD_LINEMERGE = false

I have several json objects (each on its own line) merged into one event. Best of problem is shown in the screenshots:

  1. merged objects: http://take.ms/9q90D
  2. line breaks proof: http://take.ms/u92oi

I tried some other tweaks found here, but nothing happens. I hope very much for your help. Thanks in advance.

Sorry for passive links, limitations for new user.

1 Solution

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

View solution in original post

markthompson
Builder

Hi Paulelms, can you tell me if it's showing Sourcetype=testudp on your events, if not, please re-configure your UDP input with the following settings;

  1. Restart your Splunk instance (ensuring props.conf is saved first)
  2. On the new UDP input, select sourcetype = testudp

After doing the above, it should recognise the sourcetype being testudp and then will implement the SHOULD_LINEMERGE attribute.

paulelms
Explorer
0 Karma

markthompson
Builder

Ok, so restart your splunk instance, and then go to New UDP input, and select from the SOURCETYPE dropdown, the testUDP sourcetype, not the source.

Hope this helps

paulelms
Explorer

Thanks Sir!!!

0 Karma

markthompson
Builder

No problem

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...