Deployment Architecture

Index Line Breaks

Daniel_Edwards
Explorer

Hello,

I'm getting input from a log file the contents of which are a long listing a directory containing .rpm files. When I search on the source or sourcetype I get a singe event for every line in the log file. When I search on the index I directed the input to go to, it lumps entries together:

-rw------- 1 root root 1.2M Sep  3 13:17 cyrus-sasl-2.1.22-7.el5_8.1.x86_64.rpm
-rw------- 1 root root 127K Sep  3 13:15 cyrus-sasl-lib-2.1.22-7.el5_8.1.i386.rpm

Is one event instead of two.

props.conf looks like this:

[sourcetype::RHEL_mon_log]
MUST_BREAK_AFTER = <\Q.rpm\E>
SHOULD_LINEMERGE=true

Any suggestions?

Tags (2)
0 Karma
1 Solution

Daniel_Edwards
Explorer

Via Ayn:

  Confirm that the sourcetype in your props.conf matches what sourcetype is actually in splunk.

View solution in original post

0 Karma

Daniel_Edwards
Explorer

Via Ayn:

  Confirm that the sourcetype in your props.conf matches what sourcetype is actually in splunk.
0 Karma

Daniel_Edwards
Explorer

I think you have have helped me solve the problem! I believe the sourcetype I had in my props.conf was incorrect. It needed to be [rhel_update_log] and not [RHEL_mon_log] Thank you very much.

0 Karma

Ayn
Legend

OK, and the other search, for source/sourcetype?

Daniel_Edwards
Explorer

The search I'm using is "index=rhel_update_mon". I'm relatively new to splunk so I'm trying to do the KISS thing and move on once I have a good understanding of the basics.

0 Karma

Ayn
Legend

I can see that, because there's no reason why it would act like that. Could you please post more details about your searches?

Daniel_Edwards
Explorer

I know, I had a co-worker of mine who's more knowledgeable than I take a look and he was confused as well.

0 Karma

Ayn
Legend

I don't really get it - you're directing these logs to a particular index, and you get different results if you do "index=theindex" than if you do "sourcetype=thesourcetype"?? That sounds very weird to me...

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...