Hello
I have a file with 30 lines that want to register in Splunk.
After you have configured the inputs.conf the splunk _raw saved one, with all lines of the file, when they should be 30 _raw
This is my configuration inputs.conf
I will be failing in something?
[monitor:///var/log/splunk/data_clientes.log]
index = main
source = txt
host = SIEM
SourceType = customers
disabled = false
This doesn't have anything to do with what you configure in inputs.conf, rather it's related to how Splunk is breaking data into events. For more information, read here: http://docs.splunk.com/Documentation/Splunk/6.0.2/Data/Indexmulti-lineevents