I have a one line script that searches the /dev directory for non-device (ie, regular files) on three different Red Hat 5.7 servers. On two of the three I'll get one event with multiple lines. For example, the find command will return 27 results and they get indexed as one event. This is how I expect it to be.
On the 3rd system each line that find returns gets indexed individually and the timestamp of the event looks like it's taken from the data itself - and is not assigned by the indexer.
So, if the three systems are virtually the same why the difference in how things are being indexed?
... View more