I collect script logs from light forwarders to indexers directly. Logs looks like:
When in automatically parses on splunk i got fields 348788934=Y, 304394493=N and so on...
I did props.conf on indexers:
but still not working, can anybody help?
Hi is it a multiline event? if yes, could you please put an example of an entire raw event.
will correct myself
logs starting with 0, but next goes letter, like this:
0HFGHWGHR = "Y";
0RURURIIRJS = "N";