I have multi-line (Json) events and have configured the import by
NO_BINARY_CHECK=1
BREAK_ONLY_BEFORE = ^ {
KV_MODE = json
MAX_EVENTS = 10000
MAX_TIMESTAMP_LOOKAHEAD = 14
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = true
TIME_PREFIX = "startTime":
TRUNCATE = 0
pulldown_type=1
but splunk still breaks the event after 257 lines.
best regards Marco