Hello. I am in problem.
I have log like this.
1.example.log
2022/08/24 12:04:00,ExampreA,"xxx"xx"xxx"xxxx"xxx"xxxx"xxxxx"
I'd like to replace 「"」 with blank when transferring logs to Indexer and I'd like to keep the first and last「"」.
I tried edit config file「props.conf」(Indexer).
#props.conf
[sourcetype value]
SEDCMD-replacespaces = y/"/ /
Result is that all「"」were replaced 「 」.
I want to to capture log like this.(↓)
1.example.log
2022/08/24 12:04:00,ExampreA,"xxx xx xxx xxxx xxx xxxx xxxxx"
Please Any advise.
... View more