Hi everyone,
For one of our client we are sending in json log data via log4j2 to the splunk cloud HEC token.
we are using the /event/collector/raw endpoint.
What I notice is that the fields are not extracted consistently. We do not see any pattern in our process so we cannot pinpoint the exact location of the issue.
dhuynh_0-1686606054908.png
I am using the following source type with its configs:
dhuynh_2-1686606398965.png
Hopefully can someone see what might cause this issue.
Thankyou in advanced.
Duy
... View more