I'm using Splunk cloud, i have jenkins logs indexed to my system but for some reason breaks
I took an output example and add it to Splunk with the "Add Data" option and there it looks ok but when im searching for the sourcetype it is still broken.
What is the best way to parse jenkins logs ?
this is my sourcetype configuration :
[ console_logs ]
and i want it to be shown with the bulks :
<time> Started by user