My Source is python. In WSDL I have 20 items . While am executing the query in splunk . I am getting all 20 items coming in single event. Though unable to extract the fields and show it's count. How can i get all 20 items into individual events. How can i achieve it.
Thanks
You would have to tell Splunk how to split the events. You can do this by setting the LINE_BREAKER field in a props.conf file in an app in your indexers.
If you could post a sample of your event (with sensitive data removed) and a rough description of your splunk setup (single machine or distributed?), then it would be easier to give you more specific pointers.