All Apps and Add-ons

How do I configure Ironstream and/or Splunk to treat events individually, rather than aggregating events by seconds?

kcarlin0407
New Member

How do I configure Ironstream and/or Splunk to treat events individually, rather than aggregating events by time?
I'm sending many events per second to Splunk via Ironstream, and often there are 3 or more events getting indexed as one event.

Tags (1)
0 Karma

jeastman
Path Finder

I always tell our customers to use the following parameters in their props.conf file for sourcetype=syncsortMF

SHOULD_LINEMERGE = false
LINE_BREAKER = \"}$

0 Karma

lguinn2
Legend

You probably need to set the line-breaking rules for the data in props.conf
If each event is a single line, the only setting that you probably need is

SHOULD_LINEMERGE = false

For more detailed help from the Answers community, we need to see a sample of the data stream (obfuscated of course).

You can also read more about this in the documentation: Configure event line breaking

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...