<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinEventLogs breaking the field extractions when sent to a third-party. Why? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLogs-breaking-the-field-extractions-when-sent-to-a-third/m-p/330783#M61304</link>
    <description>&lt;P&gt;You probably need to look at CLONE_SOURCETYPE.  What that will do is copy the events from their initial state into another sourcetype, where the same events can proceed to be handled in a different way.   &lt;/P&gt;

&lt;P&gt;@rphilllips posted a really good description and use case over here - &lt;A href="https://answers.splunk.com/answers/556300/how-can-i-use-clone-sourcetype-to-send-a-cloned-mo.html?childToView=556305#answer-556305"&gt;https://answers.splunk.com/answers/556300/how-can-i-use-clone-sourcetype-to-send-a-cloned-mo.html?childToView=556305#answer-556305&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Sep 2017 23:29:48 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2017-09-12T23:29:48Z</dc:date>
    <item>
      <title>WinEventLogs breaking the field extractions when sent to a third-party. Why?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLogs-breaking-the-field-extractions-when-sent-to-a-third/m-p/330782#M61303</link>
      <description>&lt;P&gt;Im able to Send the WinEventlogs to third party server through SYSLOG TCP port. But the props which i have created is breaking Field Extractions  in TA_windows Addon. please Help me in solving the issue. below are the configurations which i used:&lt;/P&gt;

&lt;P&gt;outputs.conf:&lt;/P&gt;

&lt;P&gt;[syslog:my_syslog_group]&lt;BR /&gt;
server = abcappls.abc.com:814&lt;BR /&gt;
type = tcp&lt;/P&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;P&gt;[source::WinEventLo*]&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD=30&lt;BR /&gt;
LINE_BREAKER = (&lt;A href="https://community.splunk.com/?=d%7B2%7D/d%7B2%7D/d%7B2,4%7D%20d%7B2%7D:d%7B2%7D:d%7B2%7D%20%5BaApPmM%5D%7B2%7D" target="_blank"&gt;\r\n&lt;/A&gt;)&lt;BR /&gt;
KV_MODE=none&lt;BR /&gt;
TRANSFORMS-routing = send_to_syslog&lt;BR /&gt;
SEDCMD-win=s/(?mis)(Token Elevation Type indicates|This event is generated|Application Id=).*$//g&lt;BR /&gt;
SEDCMD = s/[\n\r\t]/ /g&lt;/P&gt;

&lt;P&gt;transforms.conf :&lt;/P&gt;

&lt;P&gt;[send_to_syslog]&lt;BR /&gt;
REGEX = .&lt;BR /&gt;
DEST_KEY = _SYSLOG_ROUTING&lt;BR /&gt;
FORMAT = my_syslog_group&lt;/P&gt;

&lt;P&gt;I get the events as one liner to the third party system (which is correct) but my new PROPS have changed the Existing props which in turn  get every thing as one line to splunk Indexer as well.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;09/11/2017 09:38:32 PM  LogName=Application  SourceName=vmStatsProvider  EventCode=256  EventType=0  Type=Information  ComputerName=qwerty.loutap.chgfms.abcf  TaskCategory=General  OpCode=Info  RecordNumber=1234567  Keywords=Classic  Message=The "vmStatsProvider" is successfully initialized for this Virtual Machine. WMI namespace: "rofhjgfv2".&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;please help me with props.conf  which should not change the Fields which are getting indexed into Indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLogs-breaking-the-field-extractions-when-sent-to-a-third/m-p/330782#M61303</guid>
      <dc:creator>cleelakrishna</dc:creator>
      <dc:date>2020-09-29T15:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: WinEventLogs breaking the field extractions when sent to a third-party. Why?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WinEventLogs-breaking-the-field-extractions-when-sent-to-a-third/m-p/330783#M61304</link>
      <description>&lt;P&gt;You probably need to look at CLONE_SOURCETYPE.  What that will do is copy the events from their initial state into another sourcetype, where the same events can proceed to be handled in a different way.   &lt;/P&gt;

&lt;P&gt;@rphilllips posted a really good description and use case over here - &lt;A href="https://answers.splunk.com/answers/556300/how-can-i-use-clone-sourcetype-to-send-a-cloned-mo.html?childToView=556305#answer-556305"&gt;https://answers.splunk.com/answers/556300/how-can-i-use-clone-sourcetype-to-send-a-cloned-mo.html?childToView=556305#answer-556305&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 23:29:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WinEventLogs-breaking-the-field-extractions-when-sent-to-a-third/m-p/330783#M61304</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-12T23:29:48Z</dc:date>
    </item>
  </channel>
</rss>

