I have multi-line (Json) events and have configured the import by
NO_BINARY_CHECK=1
BREAK_ONLY_BEFORE = ^ {
KV_MODE = json
MAX_EVENTS = 10000
MAX_TIMESTAMP_LOOKAHEAD = 14
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = true
TIME_PREFIX = "startTime":
TRUNCATE = 0
pulldown_type=1
but splunk still breaks the event after 257 lines.
best regards
Marco
Hi,
Are you applying the settings in the right place? Could be an issue of the config file precedence and/or where in the deployment (forwarder/indexer phases) the configurations is made.
Plaese see;
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles
http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings
Hope this helps,
Kristian
And you do this on the indexer? Or the forwarder?
Hi Kristian,
I do it in the $SPLUNK_HOME/etc/system/local/props.conf and it seems that this have the highest priority so I wonder why the MAX_EVENTS = 10000 takes no effect.
Is there any condition for MAX_EVENT lets work?
best regards
Marco