Hi, I'm a new Splunk user and am using the TA-meraki tool downloaded from Spunkbase. Our appliance is a Meraki MX 100. We are using the free version of Splunk. As you can see from the attached screenshot, we are getting some strange results for the User field. In probably 80% of the logs, the user shows up correctly, however, sometimes it pulls a partial URL instead.
In the attached example, you can see that in the first log, the user=Rick which is correct. In the second log, the user=part of the url plus the user name. Splunk highlights the user field for Christy but then fills the User field with the wrong string.
Thanks for any help you can provide on this. Let me know if you need additional details.
... View more