i have faced problem with Qradar and transformation of log (Trend micro)
i forwarded the log as a raw format from splunk HF to Qradar
i'm facing problem with the header of the events on Qradar they have double hostname and timestamp (date)
i tried to define syslogSourcetype = sourcetype::<sourcetype>
but same occuers they are double
is there a way to solve this problem please i'm trying now for 1 week to solve this issue
Thanks