[英]splunk is reporting each line of stacktrace as a separate event
The paucity of information about the events make it hard to be specific about the solution.有关事件的信息很少,因此很难具体说明解决方案。 You need to update the props.conf settings for that sourcetype so the multiple lines of the traceback are merged into a single event.
您需要更新该源类型的 props.conf 设置,以便将多行回溯合并为一个事件。 There are a number of ways to do that, including
SHOULD_LINEMERGE=true
and BREAK_ONLY_BEFORE_DATE=true
.有很多方法可以做到这一点,包括
SHOULD_LINEMERGE=true
和BREAK_ONLY_BEFORE_DATE=true
。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.