When looking inside the forwarded Events everything looks as it should, only what is displayed in Splunk is wrong.
Help really appreciated!
Thanks and Regards
One additional question: The forwarded events are stored in a event file. Are they also stored within the SQL DB which Logbinder creates? Only relying on this file seems a bit crazy to me? How is Splunk crawling this file?