Hi
I have a plunk server and it reads the logs from our web servers. Weve recelty added on the end the %T %D time flag. Splunk just shows this as other.
Ive tried a few things to add it to the transforms file and props file but nothing works. How can I add these flags so they are seen correctly?
Matt
Hi,
Can you post the contents of props.conf and transforms.conf here ? That will help in debugging the issue.
Regards,
Amit Saxena