When I search for Windows Event Logs using :
I'm not getting any parsing/syntax highlighting or field extractions happening. The results are simply the raw XML. I have checked that I am in List format!
If I search for other indexes and sourcetypes I am getting correct parsing/syntax highlighting and extractions.
How can I go about finding out why this is happening and fix it?
Make sure you are in Verbose mode and that the Windows TA is installed on your search head.
I am in Verbose mode and the TA is installed on the search head