Getting Data In

Event Breaks at line 257

jpraman2000
New Member

Events always breaks at line 257. I have made changes to props.conf file under system/local in forwarder. But for some reason it is not working. Below are the props.conf settings

[source]
MAX_EVENTS = 5000
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE_DATE = True

Tags (1)
0 Karma

linu1988
Champion

Hello,
It is not a heavy forwarder, you need t place the props.conf file in indexer. If data already indexed. Please delete them and re-index to fid the desired result.

Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...