Splunk Enterprise

Why is Splunk deleting 0 during parsing?

bosseres
Contributor

Hello, everyone!

I collect script logs from light forwarders to indexers directly. Logs looks like:

0348788934="Y";

0304394493="N";

0874844788="Y";

etc.

 

When in automatically parses on splunk i got fields 348788934=Y, 304394493=N and so on...

I did props.conf on indexers:

 

[my_sourcetype]

FIELD_DELIMETERS=;

 

but still not working, can anybody help?

Thank you

Labels (2)
0 Karma

mayurr98
Super Champion

Hi is it a multiline event? if yes, could you please put an example of an entire raw event.

bosseres
Contributor

will correct myself

logs starting with 0, but next goes letter, like this:

0HFGHWGHR = "Y";

0RURURIIRJS = "N";

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...