I've scoured Google and Answers, but my XML looks a little different than most I've seen so far:BatchName GOCLM36962920190214001_19045SCLM000018 GUID ph_Template phEmp_Template -Initial – Company phPhy_Template
I'd like to get Splunk to display the field_value as the value and field_name as the name of the field. I've tried
props.conf:
DATETIME_CONFIG = CURRENT
SHOULD_LINEMERGE = false
BREAK_ONLY_BEFORE = /
What am I doing wrong here?
↧