Replies: 1 comment
-
I wrote the following query:
and output is:
How can I remove extra information like |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I am sending Windows Event Logs to Grafana Loki server via Grafana Alloy. Windows logs are probably in XML format. Something like below:
I want to extract the hostname, username, file or folder name, and date and time information from IDs 4660 and 4663. I wrote a query like the following:
The output is as follows:
2025-02-16 13:14:39.127 DESKTOP-1PNH21K | | 2025-02-16T09:44:39.1272425Z | | | An attempt was made to access an object
As you can see, it is not possible to extract information from the
event_data
section.How to solve it?
Thank you.
Beta Was this translation helpful? Give feedback.
All reactions