what is the equivalent of Splunk should_linemerge in Cribl?
Srinath Dayala
Posts: 10 ✭
in Stream
I am getting data into Cribl and it is by default breaking on each line (also when there is no timestamp). So, i have added manual event breaking based on timestamp. But it still the same behavior. Is there a way to disable line breaking on each line?
Tagged:
0
Answers
-
Also tried with regex event breaking. that also not working.
0 -
If you can provide a sample of your event data structure, I might be able to provide an event breaker.
Also, please review this blog and video
0