Getting Data In

What is the search query to get the events which are having linebreaking , data parsing, timestamp configuration issue?

lksridhar
Explorer

Hi Folks,

What is the search query to get the events details which are having line breaking, data parsing and timestamp configuration issue?

0 Karma
1 Solution

adonio
Ultra Champion

Hello there,

try the following search:

index=_internal sourcetype=splunkd source=*splunkd.log (component=AggregatorMiningProcessor OR component=LineBreakingProcessor) (log_level=WARN OR log_level=ERROR)

hope it helps

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

I wrote an application to determine this issue and a variety of other scenarios, it's called Alerts For Splunk Admins .
I have an update or two coming in the next two week but your scenario is likely covered the savedsearches.conf is in github

0 Karma

adonio
Ultra Champion

Hello there,

try the following search:

index=_internal sourcetype=splunkd source=*splunkd.log (component=AggregatorMiningProcessor OR component=LineBreakingProcessor) (log_level=WARN OR log_level=ERROR)

hope it helps

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...