Hi! Hope all are fine, and thanks in advance for any help
I'm having problems ingesting Linux Audit Log. For some reason, a weird field delimiter is not being correctly interpreted by Splunk. I'm pasting the examples
How can I get rid of this and get fields "data" and "UID" correctly separated?
chthies_0-1652383648745.png chthies_1-1652383661450.png chthies_2-1652383669224.png
... View more