Got multiple lines of logs grouped in single log line entry
Pinned Sometimes single logline in sumologic contains more than 10 lines of log.
Did anyone encounter similar problem? Anyone can explain how sumologic group its log lines?
-
Official comment
Ran,
Sumo Logic tries it's best to identify what a log message entails, from beginning to end; however, if there's a lot of variability in your log messages, Sumo might not be able to automatically detect this, as it sounds to be your case.
Good news is that you can specify what the boundary of a message should be so that Sumo can correctly break your log lines into meaningful messages. See details on how to do it here: http://help.sumologic.com/Send_Data/Sources/01Sources_for_Installed_Collectors/Local_File_Source/Define_Boundary_Regex_for_Multiline_Messages
Hope this helps!
Cheers,
Mario
Comment actions -
Please use the following link:
-
Updated Link for 2022
Please sign in to leave a comment.
Comments
6 comments