I am running into an issues where I am attempting to import data from a SQL Server database, one of the columns is entitled message, contains message payload with the character '{' in it. When Splunk Process the data from DB Connect, it inappropriately truncates the message when it sees the '{' bracket in the document. Are there solutions for overriding this line breaking feature? We currently have to go into Raw to extract the information using RegEx to preserve the data and we would rather store this message in a Splunk Key Value Pair.
Please share a sanitized sample event and the props for the sourcetype.