we are using splunk cloud and getting juniper OS logs as syslogs from Heavy forwarder to splunk cloud.
but in splunk cloud fields are not breaking
we have installed in juniper addon in splunk cloud
do this need should there at Heavy forwarder end so that parsing will happen
Line breaking and some field extraction is performed by the heavy forwarder so the add-on must be installed there as well.