Hi, as a french user i use render_XML to get internationnal formated windows log.
but the xml event is one lined, recognition is ok by splunk but ends with an non firendly one lined event :
4624 0 0 12544 0 0x8020000000000000 224280055 Security server.domain S-1-0-0--0x0S-1-5-21-xxxxxxxxxxxxxxxx-xxxxxxxxxxxx-xxxxxxxxxxduponddomainxxxxxxxx3NtLmSsp NTLMServer{00000000-0000-0000-0000-000000000000}-NTLM V11280x0-255.255.255.25456443
do you have any solution to transform it to a nicer looking :
4624 0 0 12544 0 0x8020000000000000 224280055 Security server.domain S-1-0-0--0x0S-1-5-xx-xxxxxxx-xxxxxxxx-xxxxxxxxxxxxxx-xxxxJeanDupond......3NtLmSsp NTLMserver{00000000-0000-0000-0000-000000000000}-NTLM V11280x0-255.255.255.25456443
any way to add return or backspace to event ?
↧