Splunk Enterprise

Why is Splunk deleting 0 during parsing?

bosseres
Contributor

Hello, everyone!

I collect script logs from light forwarders to indexers directly. Logs looks like:

0348788934="Y";

0304394493="N";

0874844788="Y";

etc.

 

When in automatically parses on splunk i got fields 348788934=Y, 304394493=N and so on...

I did props.conf on indexers:

 

[my_sourcetype]

FIELD_DELIMETERS=;

 

but still not working, can anybody help?

Thank you

Labels (2)
0 Karma

mayurr98
Super Champion

Hi is it a multiline event? if yes, could you please put an example of an entire raw event.

bosseres
Contributor

will correct myself

logs starting with 0, but next goes letter, like this:

0HFGHWGHR = "Y";

0RURURIIRJS = "N";

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...