Hi all,
Me and my team have noticed that from a number of emails traffic submitted by mimecast, the Subject in the email have a Pipe symbol "|" something like the following:
You will get this | You wont get this | either this
Splunk only add "You will get this" in the Subject field, rather than the whole string, is there anything I need to change in the extraction or is an issue in the MimeCast side?