Hello, everyone!
I collect script logs from light forwarders to indexers directly. Logs looks like:
0348788934="Y";
0304394493="N";
0874844788="Y";
etc.
When in automatically parses on splunk i got fields 348788934=Y, 304394493=N and so on...
I did props.conf on indexers:
[my_sourcetype]
FIELD_DELIMETERS=;
but still not working, can anybody help?
Thank you
Hi is it a multiline event? if yes, could you please put an example of an entire raw event.
will correct myself
logs starting with 0, but next goes letter, like this:
0HFGHWGHR = "Y";
0RURURIIRJS = "N";