All Apps and Add-ons

How do I configure Ironstream and/or Splunk to treat events individually, rather than aggregating events by seconds?

kcarlin0407
New Member

How do I configure Ironstream and/or Splunk to treat events individually, rather than aggregating events by time?
I'm sending many events per second to Splunk via Ironstream, and often there are 3 or more events getting indexed as one event.

Tags (1)
0 Karma

jeastman
Path Finder

I always tell our customers to use the following parameters in their props.conf file for sourcetype=syncsortMF

SHOULD_LINEMERGE = false
LINE_BREAKER = \"}$

0 Karma

lguinn2
Legend

You probably need to set the line-breaking rules for the data in props.conf
If each event is a single line, the only setting that you probably need is

SHOULD_LINEMERGE = false

For more detailed help from the Answers community, we need to see a sample of the data stream (obfuscated of course).

You can also read more about this in the documentation: Configure event line breaking

Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...