I am having a similar issue however in my case the field always has a suffix of sophos_event_input after the username. Example User Joe-Smith, Adams sophos_event_input Jane-Doe, Smith sophos_event_input I would like to change the User field to User Joe-Smith, Adams Jane-Doe, Smith Basically I want to get rid of the sophos_event_input suffix. How will I go about this?
... View more
Did you solve this @ljalvrdz - im having an identical issue. have tried across splunk enterprise 7.1.2 and over the weekend upgraded to 8.0.3, but still no joy. Any help appreciated, thanks!
... View more