The Message field of wineventlog is being handled by the default configurations or of the TA and I would like to change it but I can't find out which props/transforms do the current extractions.
The Message field is of multiple lines and the extraction, at the moment, is applied on each line, extracting the name, value pairs separated by a colon.
In the case of Avecto, we see within one line multiple name value pairs and the pairs are separated by commas.
Hi @danielbb
did you try to use btool option?
splunk btool props list --debug
anyway I share the documentation
I ran -
splunk btool transforms list --debug > /tmp/transforms.all
cat transforms.all | grep -i '$1::$2'
The second one returns 29 lines and I would like to know which one is being applied.
Hi @danielbb
usually the conf files have this priority
Now I don't know where are located your conf files but generally if is present on the local app the conf file have a priority.
anyway I share this interesting article
I can't find out where Message is being processed for WinEventLog. I scanned props and transforms with btool and can't find it.