Deployment Architecture

splunk gets confused after log is rotated by my app server restart

scott74nyc
New Member

My app server gets restarted once a day. Sometimes, Splunk will treat individual lines as unique log entry. So what should be one log entry becomes multiple log entries. For example,

The below log should be one log but shows up as 4 log entries in Splunk.

[Date] [Time] [ERROR] message line 1
message line 2
message line 3
message line 4

Can anyone advice me on fixing this occasional issue?

0 Karma

scott74nyc
New Member

My log entry line break is not showing up. This is how it should look like

[Date] [Time] [ERROR] message line 1
message line 2
message line 3
message line 4

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...