I have to break events based on the hex message delimiter. When I ingest data into Splunk, it is showing as letter 'x' or whitespace between events. How do I break events at the hex message delimiter?
Hi ankithreddy777,
I think you can try the following in props.conf:
FIELD_DELIMITER =
* Tells Splunk which character delimits or separates fields in the specified file or source.
* This attribute supports the use of special characters.
Hope it helps. Thanks!
Hunter
Probably 'REPORT' in props.conf and 'DELIMS' in transforms.conf.
More information would be nice.
Sample entries please..