@gcusello please have a look at below [ __auto__learned__ ]
SHOULD_LINEMERGE=true
LINE_BREAKER=(\{\"eventDetails\"\:)
NO_BINARY_CHECK=true
SEDCMD-tailchars=s/(.*\"\}{1}).*/\1/g Added SEDCMD class to remove unwanted characters at end of the line. you need to deal with pre-text which is in first event.
... View more
What software/hardware are you using as a reverse proxy? And how is that set up?
Any info on what is inside the following two files could also be helpful.
$SPLUNK_HOME/var/log/splunk/web_access.log
$SPLUNK_HOME/var/log/splunk/web_service.log
Also the logfiles for the reverse proxy could be helpful.
... View more