All Apps and Add-ons

Why is the JMS Messaging Modular Input removing line breaks from events in queue?

kurtzschmitt
Engager

The data is going into an existing tool that is able to handle line breaks properly (see screenshot #1). When the JMS Messaging Modular Input pulls the data into Splunk, the events show up with all the data run together, with no line breaks (see screenshot #2). We checked to make sure it’s nothing being done via props/transforms, and the sender of the data to the queue has confirmed he’s not manipulating it on his side. I assume that means it must be something done via the JMS classes or other config files.

Any ideas as to why the line breaks are being removed?

SS#1:
alt text

SS#2:
alt text

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Uncheck the strip newline characters from message body option.

alt text

View solution in original post

Damien_Dallimor
Ultra Champion

Uncheck the strip newline characters from message body option.

alt text

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...