I have a custom log with the following preview:
Message="An account was successfully logged on." Security_ID="NT AUTHORITY\SYSTEM\nNT AUTHORITY\SYSTEM" Account_Domain="xxxxx\nNT AUTHORITY" Logon_Type="5"
When it's ingested into splunk, the fields extracted are
Message: An account was successfully logged on.
Account_Domain: xxxxx nNT AUTHORITY
Security_ID: NT AUTHORITY\SYSTEM\nNT AUTHORITY\SYSTEM
Logon_Type: 5
As you can see, the \n is not being broken down into multivalues.
What should i modify, so that the output will be as such
Message: An account was successfully logged on.
Account_Domain: xxxxx
NT AUTHORITY
Security_ID: NT AUTHORITY\SYSTEM
NT AUTHORITY\SYSTEM
Logon_Type: 5
I've tried modifying and playing around with props.conf , transforms.conf but to no avail.
Appreciate any help!
... View more