Thank you for your reply, First, let me talk a little bit about my setting. I used regex101 to check the line-break in my config. About the timestamp, it matched with all the events. I just tried your settings, it did not work. of course, props.conf in /system/local and restart Splunk. Any other ideas, sir?
... View more