Heading 1 - Splunk

SHOULD_LINEMERGE: Tells Splunk not to engage line merging (break on newlines and merge on timestamps), which is known to be a huge resource hog, especially for multiline events. Instead, by defining LINE_BREAKER we're telling it to break on a definite pattern. TRUNCATE: maximum line length (or event length) in bytes. This defaults to 10K. ................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download