Knowledge Manager Manual

 


Overview of multiline events and event linebreaking

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Overview of multiline events and event linebreaking

Some events are made up of more than one line. Splunk handles most of these kinds of events correctly by default, but you may encounter examples of multiline events that Splunk doesn't recognize properly by default.

For more information about changing Splunk's default linebreaking behavior, see "Index multi-line events" in the Admin manual.


Multiline event linebreaking and segmentation limitations

Splunk does apply limitations to extremely large events when it comes to linebreaking and segmentation.

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!