In my logs we have, special character like \r\n\t, i like remove from events while index level. Please help me on this.
Example: we have like this events\r\n\t\t\t\t\t
Splunk provides a way to mask sensitive data (replace sensitive data with different string). You can use same concept to replace those junk character with nothing (effectively removing them from raw data). See this for more information.
Again, a better option would to be to fix the source that generates the data.
The best way is to do this:
SHOULD_LINEMERGE = false
LINEBREAKER = ([\r\n\t]+)