Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how to remove multiple logs into single event

$
0
0
[tomcat] EXTRACT = \/u01\/logs\-(?\w+)\/.* in source ### Adding the below to BREAK EVENTS only at timestamp and TRUNCATING issue BREAK_ONLY_BEFORE = (\d+[- :,-w]+) MAX_TIMESTAMP_LOOKAHEAD = 30 TRUNCATE = 0 We are facing an issue with multiple logs in a single event for only tomcat as the sourcetype, May I know the reason for it. we also have SHOULD_LINEMERGE=true for other sourcetype should I include SHOULD_LINEMERGE=false for the tomcat. Any help will be appreciated.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>