Splunk Search

Why is Splunk not displaying the full log entry?

vcorral
New Member

I am only receiving the first two lines of a log entry into Splunk:

Date: 2019/03/12 14:00:10
SOFTWARE Module: D:\SOFTWARE_Enterprise\Service6.exe Machine Name: TESTSERVER001T Database Name: ORA-TEST

When the full entry should be:
Date: 2019/03/12 14:00:10
SOFTWARE Module: D:\SOFTWARE_Enterprise\Service6.exe Machine Name: TESTSERVER001T Database Name: ORA-TEST
Product Version: Release X.XX.XX.XX Jul 20 2018 11:57:17
Source id: Device <7616>
Software Integration Service Unavailable

Other log entries from other indexes are displaying the full log entries until they reach the truncate size, and this one is shorter than those. Any thoughts on where I can look to fix this would be appreciated.

Regards,
Virgil

0 Karma

vcorral
New Member

So I figured this out. my props.conf file did not have anything set for the "BREAK_ONLY_BEFORE = ".
I added "Date:" to the line and now it works.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...