A developer made a change to the logging that they were managing. They added a new Key Value Pair and the results now have spaces ie Operation=Web Service Call: callABCService. Splunk Search is classifying this as Operation=Web. Is there a quick fix that I can make in Transforms or Props to work around this?
Thank you
Is each KV pair on a line by itself? If so you can just do something like the following:
props.conf
REPORT-bad_dev_format = kv-spaces
transforms.conf
[kv-spaces]
DELIMS = "\n","="
Otherwise paste a copy of an event and maybe we can suggest a transforms solution.
Easiest way is to get the developer to quote their output. So Operation="Web Service Call: callABCService".
I have a similar problem, but with a product I can't change the logging on, so any other advice would be wonderfully helpful.
Whats the rest of the raw event look like ?