<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Converting log events to metrics using existing fields in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395839#M96458</link>
    <description>&lt;P&gt;When metrics are involved it's more than just defining the sourcetype. Standard fields need to be defined to play well with metrics store.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MOverview"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MOverview&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Nov 2018 16:52:03 GMT</pubDate>
    <dc:creator>brent_weaver</dc:creator>
    <dc:date>2018-11-18T16:52:03Z</dc:date>
    <item>
      <title>Converting log events to metrics using existing fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395837#M96456</link>
      <description>&lt;P&gt;Good morning all, I am reading docs on how to create sourcetypes for metrics but none go into how to just use fields instead of regex. I am using fluentbit to send metrics to HEC (and it works perfectly) in JSON format. &lt;/P&gt;

&lt;P&gt;How do I use the existing fields to rewrite the sourcetype as metrics? &lt;/P&gt;

&lt;P&gt;I included a screenshot of what the events look like.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6131i760D7F5F0DCC65A1/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 13:05:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395837#M96456</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2018-11-18T13:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Converting log events to metrics using existing fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395838#M96457</link>
      <description>&lt;P&gt;Can’t you define the sourcetype when you setup the HEC token?&lt;/P&gt;

&lt;P&gt;Would you want to change the sourcetype there?&lt;/P&gt;

&lt;P&gt;There is a sourcetype rename feature in the settings drop down under fields I believe.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 14:44:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395838#M96457</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-11-18T14:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Converting log events to metrics using existing fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395839#M96458</link>
      <description>&lt;P&gt;When metrics are involved it's more than just defining the sourcetype. Standard fields need to be defined to play well with metrics store.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MOverview"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MOverview&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 16:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395839#M96458</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2018-11-18T16:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Converting log events to metrics using existing fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395840#M96459</link>
      <description>&lt;P&gt;Ok so you don’t want to “rewrite the sourcetype as metrics”...&lt;/P&gt;

&lt;P&gt;This was somewhere on the link you gave, does it make sense?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MConfiguration"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MConfiguration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 18:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Converting-log-events-to-metrics-using-existing-fields/m-p/395840#M96459</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-11-18T18:54:48Z</dc:date>
    </item>
  </channel>
</rss>

