Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Multiple sources in event

$
0
0
Hi. We are ingesting log from a HEC input where in the stanza we are setting a source. In the events there is a field called Source that is extracted into an other source (in search time) Meaning all events having 2 source with different names. Any suggestion on how to solve this issue?

Viewing all articles
Browse latest Browse all 47296

Trending Articles