<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log formatting not as expected in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748830#M119005</link>
    <description>&lt;P&gt;This is... bad,&lt;/P&gt;&lt;P&gt;Firstly, it seems that it's data already received by something else, embedded in another format and sent to Splunk.&lt;/P&gt;&lt;P&gt;Then secondly, these are completely different sourcetypes. So if you absolutely cannot separate them earlier, you should overwrite sourcetype on ingestion so that each of those types is parsed differently.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jun 2025 18:05:16 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-06-26T18:05:16Z</dc:date>
    <item>
      <title>Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748788#M118985</link>
      <description>&lt;LI-CODE lang="markup"&gt;Jun 26 13:46:12 128.23.84.166 [local0.err] &amp;lt;131&amp;gt;Jun 26 13:46:12 GBSDFA1AD011HMA.systems.uk.fed ASM:f5_asm=PROD

vs_name="/f5-tenant-01/XXXXXXXX"
violations="HTTP protocol compliance failed"
sub_violations="HTTP protocol compliance failed:Header name with no header value"
attack_type="HTTP Parser Attack"
violation_rating="3/5"
severity="Error"

support_id="XXXXXXXXX"
policy_name="/Common/waf-fed-transparent"
enforcement_action="none"

dest_ip_port="128.155.6.2:443"
ip_client="128.163.192.44"
x_forwarded_for_header_value="N/A"

method="POST"
uri="/auth-service/api/v2/token/refreshAccessToken"
microservice="N/A"
query_string="N/A"
response_code="500"

sig_cves="N/A"
sig_ids="N/A"
sig_names={N/A}
sig_set_names="N/A"
staged_sig_cves="N/A"
staged_sig_ids="N/A"
staged_sig_names="N/A"
staged_sig_set_names="N/A"

&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;
&amp;lt;BAD_MSG&amp;gt;
&amp;lt;violation_masks&amp;gt;
&amp;lt;block&amp;gt;0-0-0-0&amp;lt;/block&amp;gt;
&amp;lt;alarm&amp;gt;2400500004500-106200000003e-0-0&amp;lt;/alarm&amp;gt;
&amp;lt;learn&amp;gt;0-0-0-0&amp;lt;/learn&amp;gt;
&amp;lt;staging&amp;gt;0-0-0-0&amp;lt;/staging&amp;gt;
&amp;lt;/violation_masks&amp;gt;
&amp;lt;request-violations&amp;gt;
&amp;lt;violation&amp;gt;
&amp;lt;viol_index&amp;gt;14&amp;lt;/viol_index&amp;gt;
&amp;lt;viol_name&amp;gt;VIOL_HTTP_PROTOCOL&amp;lt;/viol_name&amp;gt;
&amp;lt;http_sanity_checks_status&amp;gt;2&amp;lt;/http_sanity_checks_status&amp;gt;
&amp;lt;http_sub_violation_status&amp;gt;2&amp;lt;/http_sub_violation_status&amp;gt;
&amp;lt;http_sub_violation&amp;gt;SGVhZGVyICdBdXRob3JpemF0aW9uJyBoYXMgbm8gdmFsdWU=&amp;lt;/http_sub_violation&amp;gt;
&amp;lt;/violation&amp;gt;
&amp;lt;/request-violations&amp;gt;
&amp;lt;/BAD_MSG&amp;gt;​&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Jul  3 11:12:48 128.168.189.4 [local0.err] &amp;lt;131&amp;gt;2025-07-03T11:12:48+00:00 nginxplus-nginx-ingress-controller-6947cb4744-hxwf5 ASM:Log_details\x0a\x0avs_name="14-cyberwasp-sv-busybox.ikp3001ynp.cloud.uk.fed:10-/"\x0aviolations="Attack signature detected"\x0asub_violations="N/A"\x0aattack_type="Cross Site Scripting (XSS)"\x0aviolation_rating="5/5"\x0aseverity="N/A"\x0a\x0asupport_id="14096019979554169061"\x0apolicy_name="waf-fed-enforced"\x0aenforcement_action="block"\x0a\x0adest_ip_port="0.0.0.0:443"\x0aip_client="128.175.220.223"\x0ax_forwarded_for_header_value="N/A"\x0a\x0amethod="GET"\x0auri="/"\x0amicroservice="N/A"\x0aquery_string="svanga=%3Cscript%3Ealert(1)%3C/script%3E%22"\x0aresponse_code="0"\x0a\x0asig_cves="N/A,N/A,N/A,N/A"\x0asig_ids="200001475,200000098,200001088,200101609"\x0asig_names={XSS script tag end (Parameter) (2),XSS script tag (Parameter),alert() (Parameter)...}\x0asig_set_names="{High Accuracy Signatures;Cross Site Scripting Signatures;Generic Detection Signatures (High Accuracy)},{High Accuracy Signatures;Cross Site Scripting Signatures;Generic Detection Signatures (High Accuracy)},{Cross Site Scripting Signatures}..."\x0astaged_sig_cves="N/A,N/A,N/A,N/A"\x0astaged_sig_ids="N/A"\x0astaged_sig_names="N/A"\x0astaged_sig_set_names="N/A"\x0a\x0a&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;&amp;lt;BAD_MSG&amp;gt;&amp;lt;violation_masks&amp;gt;&amp;lt;block&amp;gt;400500200500-1a01030000000032-0-0&amp;lt;/block&amp;gt;&amp;lt;alarm&amp;gt;20400500200500-1ef903400000003e-7400000000000000-0&amp;lt;/alarm&amp;gt;&amp;lt;learn&amp;gt;0-0-0-0&amp;lt;/learn&amp;gt;&amp;lt;staging&amp;gt;0-0-0-0&amp;lt;/staging&amp;gt;&amp;lt;/violation_masks&amp;gt;&amp;lt;request-violations&amp;gt;&amp;lt;violation&amp;gt;&amp;lt;viol_index&amp;gt;42&amp;lt;/viol_index&amp;gt;&amp;lt;viol_name&amp;gt;VIOL_ATTACK_SIGNATURE&amp;lt;/viol_name&amp;gt;&amp;lt;context&amp;gt;parameter&amp;lt;/context&amp;gt;&amp;lt;parameter_data&amp;gt;&amp;lt;value_error/&amp;gt;&amp;lt;enforcement_level&amp;gt;global&amp;lt;/enforcement_level&amp;gt;&amp;lt;name&amp;gt;c3Zhbmdh&amp;lt;/name&amp;gt;&amp;lt;value&amp;gt;PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0PiI=&amp;lt;/value&amp;gt;&amp;lt;location&amp;gt;query&amp;lt;/location&amp;gt;&amp;lt;expected_location&amp;gt;&amp;lt;/expected_location&amp;gt;&amp;lt;is_base64_decoded&amp;gt;false&amp;lt;/is_base64_decoded&amp;gt;&amp;lt;param_name_pattern&amp;gt;*&amp;lt;/param_name_pattern&amp;gt;&amp;lt;staging&amp;gt;0&amp;lt;/staging&amp;gt;&amp;lt;/parameter_data&amp;gt;&amp;lt;staging&amp;gt;0&amp;lt;/staging&amp;gt;&amp;lt;sig_data&amp;gt;&amp;lt;sig_id&amp;gt;200001475&amp;lt;/sig_id&amp;gt;&amp;lt;blocking_mask&amp;gt;3&amp;lt;/blocking_mask&amp;gt;&amp;lt;kw_data&amp;gt;&amp;lt;buffer&amp;gt;c3ZhbmdhPTxzY3JpcHQ+YWxlcnQoMSk8L3NjcmlwdD4i&amp;lt;/buffer&amp;gt;&amp;lt;offset&amp;gt;8&amp;lt;/offset&amp;gt;&amp;lt;length&amp;gt;7&amp;lt;/length&amp;gt;&amp;lt;/kw_data&amp;gt;&amp;lt;/sig_data&amp;gt;&amp;lt;sig_data&amp;gt;&amp;lt;sig_id&amp;gt;200000098&amp;lt;/sig_id&amp;gt;&amp;lt;blocking_mask&amp;gt;3&amp;lt;/blocking_mask&amp;gt;&amp;lt;kw_data&amp;gt;&amp;lt;buffer&amp;gt;c3ZhbmdhPTxzY3JpcHQ+YWxlcnQoMSk8L3NjcmlwdD4i&amp;lt;/buffer&amp;gt;&amp;lt;offset&amp;gt;7&amp;lt;/offset&amp;gt;&amp;lt;length&amp;gt;7&amp;lt;/length&amp;gt;&amp;lt;/kw_data&amp;gt;&amp;lt;/sig_data&amp;gt;&amp;lt;sig_data&amp;gt;&amp;lt;sig_id&amp;gt;200001088&amp;lt;/sig_id&amp;gt;&amp;lt;blocking_mask&amp;gt;2&amp;lt;/blocking_mask&amp;gt;&amp;lt;kw_data&amp;gt;&amp;lt;buffer&amp;gt;c3ZhbmdhPTxzY3JpcHQ+YWxlcnQoMSk8L3NjcmlwdD4i&amp;lt;/buffer&amp;gt;&amp;lt;offset&amp;gt;15&amp;lt;/offset&amp;gt;&amp;lt;length&amp;gt;6&amp;lt;/length&amp;gt;&amp;lt;/kw_data&amp;gt;&amp;lt;/sig_data&amp;gt;&amp;lt;sig_data&amp;gt;&amp;lt;sig_id&amp;gt;200101609&amp;lt;/sig_id&amp;gt;&amp;lt;blocking_mask&amp;gt;3&amp;lt;/blocking_mask&amp;gt;&amp;lt;kw_data&amp;gt;&amp;lt;buffer&amp;gt;c3ZhbmdhPTxzY3JpcHQ+YWxlcnQoMSk8L3NjcmlwdD4i&amp;lt;/buffer&amp;gt;&amp;lt;offset&amp;gt;7&amp;lt;/offset&amp;gt;&amp;lt;length&amp;gt;25&amp;lt;/length&amp;gt;&amp;lt;/kw_data&amp;gt;&amp;lt;/sig_data&amp;gt;&amp;lt;/violation&amp;gt;&amp;lt;/request-violations&amp;gt;&amp;lt;/BAD_MSG&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;We have already implemented some platform logs in Splunk and this is the format we have for it (1st XML)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and the props.conf we have written for this in indexer -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[abcd]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TIME_PREFIX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;^&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;25&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TIME_FORMAT&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;%b&amp;nbsp;%d&amp;nbsp;%H:%M:%S&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SEDCMD-&lt;/SPAN&gt;&lt;SPAN&gt;newline_remove&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;s/\\r\\n/\n/g&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SEDCMD-&lt;/SPAN&gt;&lt;SPAN&gt;formatxml&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;s/&amp;gt;&amp;lt;/&amp;gt;\n&amp;lt;/g&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;LINE_BREAKER&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;([\r\n]+)[A-Z][a-z]{&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;}\s+\d{&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;}\s\d{&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;}:\d{&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;}:\d{&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;}\s&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SHOULD_LINEMERGE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;False&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TRUNCATE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10000&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;#&amp;nbsp;Leaving&amp;nbsp;PUNCT&amp;nbsp;enabled&amp;nbsp;can&amp;nbsp;impact&amp;nbsp;indexing&amp;nbsp;performance.&amp;nbsp;Customers&amp;nbsp;can&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;#&amp;nbsp;comment&amp;nbsp;this&amp;nbsp;line&amp;nbsp;if&amp;nbsp;they&amp;nbsp;need&amp;nbsp;to&amp;nbsp;use&amp;nbsp;PUNCT&amp;nbsp;(e.g.&amp;nbsp;security&amp;nbsp;use&amp;nbsp;cases)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ANNOTATE_PUNCT&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;false&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;props.conf on search head -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[abcd]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;REPORT-&lt;/SPAN&gt;&lt;SPAN&gt;xml_kv_extract&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;bad_msg_xml,&amp;nbsp;bad_msg_xml_kv&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;transforms.conf&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[bad_msg_xml]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;REGEX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(?ms)&amp;lt;BAD_MSG&amp;gt;(.*?)&amp;lt;\/BAD_MSG&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;FORMAT&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Bad_Msg_Xml::$&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[bad_msg_xml_kv]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SOURCE_KEY&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Bad_Msg_Xml&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;REGEX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(?ms)&amp;lt;(\w*)&amp;gt;([^&amp;lt;]*)&amp;lt;\/\&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;FORMAT&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;$&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;::$&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;MV_ADD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Now we are applying same logic for the&amp;nbsp; raw data (attached above in 2nd XML format) and now it is not at all working in readable format --&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Sometimes single event is coming as multi event. for example response code coming as one event method is coming as another event which is not supposed to be. Please help me with props and transforms modifications. We need data to be in the format I have given initially&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 03 Jul 2025 11:27:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748788#M118985</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-07-03T11:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748789#M118986</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could this is an issue with the&amp;nbsp;&lt;SPAN&gt;LINE_BREAKER, try the following which includes a negative lookahead for the date:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER=([\r\n]+)(?=[A-Z][a-z]{2}\s+\d{1,2}\s\d{2}:\d{2}:\d{2}\s)&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="livehybrid_0-1750971348256.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39512i06845A27952D0E7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="livehybrid_0-1750971348256.png" alt="livehybrid_0-1750971348256.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I just check, you said you have the props/transforms on the Indexer, is this data sent from a UF or HF? If its a HF then you'll need to deploy it there too.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 20:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748789#M118986</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-26T20:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748791#M118987</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;already checked the same via chatgpt and applied but no luck.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748791#M118987</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-06-26T14:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748792#M118988</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hmm okay, it matches via&amp;nbsp;&lt;A href="https://regex101.com/r/ZZw8Lv/1" target="_blank"&gt;https://regex101.com/r/ZZw8Lv/1&lt;/A&gt;&amp;nbsp;- must be something else, I'll keep digging.&lt;/P&gt;&lt;P&gt;Did chatgpt have any other suggestions!?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:57:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748792#M118988</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-26T14:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748793#M118989</link>
      <description>&lt;P&gt;Can you also confirm, is the data coming from a UF? I saw you put that the conf was on the Indexers but if its being sent from a Heavy Forwarder it will need to be there too.&lt;/P&gt;&lt;P&gt;Is this a regular monitor:// input?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748793#M118989</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-26T15:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748806#M118994</link>
      <description>&lt;P&gt;UF it is. Not HF.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 16:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748806#M118994</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-06-26T16:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Log formatting not as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748830#M119005</link>
      <description>&lt;P&gt;This is... bad,&lt;/P&gt;&lt;P&gt;Firstly, it seems that it's data already received by something else, embedded in another format and sent to Splunk.&lt;/P&gt;&lt;P&gt;Then secondly, these are completely different sourcetypes. So if you absolutely cannot separate them earlier, you should overwrite sourcetype on ingestion so that each of those types is parsed differently.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 18:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-formatting-not-as-expected/m-p/748830#M119005</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-26T18:05:16Z</dc:date>
    </item>
  </channel>
</rss>

