Getting Data In

monitor records several lines in one _raw

jrodriguezap
Contributor

Hello
I have a file with 30 lines that want to register in Splunk.
After you have configured the inputs.conf the splunk _raw saved one, with all lines of the file, when they should be 30 _raw
This is my configuration inputs.conf
I will be failing in something?

[monitor:///var/log/splunk/data_clientes.log] 
index = main 
source = txt 
host = SIEM 
SourceType = customers 
disabled = false
0 Karma

Ayn
Legend

This doesn't have anything to do with what you configure in inputs.conf, rather it's related to how Splunk is breaking data into events. For more information, read here: http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/Indexmulti-lineevents

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...