Hi,
i just started evaluating splunk... and i just ran into this same issue. However it looks like the settings in the props.conf are somehow ignored. There is still one big message that is not split by the \x00 string.
Any suggestions...? Im running splunk 5.0.1 build 143156
Best regards,
Markus
... View more