Hi all,
I have two sourcetypes: WinEventLog and XmlWinEventLog.
Both were displaying as very hard to read XML data in the events.
I was able to correct the WinEventLog data by editing the index.conf file from RenederXML=true to false, but it did not fix the XmlWinEventlog sourcetype data.
I think it might be the props.conf > KV_MODE = xml, but it also did not correct the parsing problem.
Any assistance would be greatly appreciated!
/Paul