Getting Data In

How to break event logs

rahulmanthena
Loves-to-Learn

In our Splunk enterprise event logs are not breaking.

Two events are coming as one event.

0 Karma

somesoni2
Revered Legend

It happens when your log data is not able to parsed correctly by Splunk automatically (if you don't have to event breaking rules defined for the sourcetype you're using and your data format is not following default Splunk's rules) OR your log data format is different from the rules you've defined for your custom sourcetype. Check what sourcetype you're using, if you've event breaking defined for that sourcetype and if log data is following that event breaking rule.

0 Karma

Sukisen1981
Champion

hi @rahulmanthena

well this is a generic question. but there are multiple options available - https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Configureeventlinebreaking

If you are struggling with something specific, please post the issue in more detauls

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...