Splunk Enterprise

Why is Splunk deleting 0 during parsing?

bosseres
Contributor

Hello, everyone!

I collect script logs from light forwarders to indexers directly. Logs looks like:

0348788934="Y";

0304394493="N";

0874844788="Y";

etc.

 

When in automatically parses on splunk i got fields 348788934=Y, 304394493=N and so on...

I did props.conf on indexers:

 

[my_sourcetype]

FIELD_DELIMETERS=;

 

but still not working, can anybody help?

Thank you

Labels (2)
0 Karma

mayurr98
Super Champion

Hi is it a multiline event? if yes, could you please put an example of an entire raw event.

bosseres
Contributor

will correct myself

logs starting with 0, but next goes letter, like this:

0HFGHWGHR = "Y";

0RURURIIRJS = "N";

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...