Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to detect the 1 liner entries in splunk?

$
0
0
For some reason, 1 liner entries are send to my splunk, after incapsula logs shifted to LEEF format. Initially, we were using CEF format. sourcetype:incapsula 1 liner log entries look like this: startTime:xxxxx startTime:xxxx endTime:xxxxxx Vendor is unable to change on their end, anything we can do the Splunk side, to make it such that the entries can be recognized by Splunk?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>