Replies: 1 comment
-
I wrote the following query:
and output is:
How can I remove extra information like |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
I am sending Windows Event Logs to Grafana Loki server via Grafana Alloy. Windows logs are probably in XML format. Something like below:
I want to extract the hostname, username, file or folder name, and date and time information from IDs 4660 and 4663. I wrote a query like the following:
The output is as follows:
2025-02-16 13:14:39.127 DESKTOP-1PNH21K | | 2025-02-16T09:44:39.1272425Z | | | An attempt was made to access an object
As you can see, it is not possible to extract information from the
event_data
section.How to solve it?
Thank you.
Beta Was this translation helpful? Give feedback.
All reactions