I want to use forwarder to forward mail logs to indexer.
However, the log forwarded from the forwarder is displayed separately from the indexer.
how can i solve it.
start character: MAIL_LOG
end character: END_MAIL
[[[forwarder log file]]]
ex1) The forwarder log file looks like this:
The log is divided.
ex1) only mail start characters logs.
ex2) only part of the message logs.
ex3) Do not include the mail start character logs. MAIL_LOG
provide the screenshot of the log file and the same data in Splunk.
I think, the issue is because of sourcetype configuration for multiline event.
Please explain more about what you mean by "the log forwarded from the forwarder is displayed separately from the indexer". Use actual example events, but hide private information.
The forwarder can check the log file in full format. However, the log is truncated on the indexer.
Your props.conf settings probably need to be adjusted. Please provide some sample events and we'll try to help you get the settings right.