On a few of our IIS servers, some one checked off a few extra fields to be logged, which is not bad to have more information, but the problem is that Splunk is treating it like the old format.
There are 4 servers with the original setup, and 2 with the new setup.
How do I tell splunk to reprocess the logs from those two sources with a new format?
... View more