I have a big file about 17G,when I input it as a file,splunk treat some record as multi-line.
The file is UTF-8 Unicode text.
how can I force splunk read file line by line ?
Thank you very much!
You need to configure props.conf in order to force splunk index data with single line.
The configuration will be following.
[your_sourcetype]
SHOULD_LINEMERGE = false
You can also refer to the manual as bellow.
http://docs.splunk.com/Documentation/Splunk/5.0/Data/Indexmulti-lineevents
it works!
Thank you !
the manual are powerful!
You need to configure props.conf in order to force splunk index data with single line.
The configuration will be following.
[your_sourcetype]
SHOULD_LINEMERGE = false
You can also refer to the manual as bellow.
http://docs.splunk.com/Documentation/Splunk/5.0/Data/Indexmulti-lineevents