- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sophos App - JSON fields renaming

JScordo
Path Finder
03-21-2019
07:25 AM
After installing the add-on and getting data into my environment from the Sophos Add-On For Splunk (https://splunkbase.splunk.com/app/4096/) I noticed that the json comes with a field named "source" which causes issues since when setting the inputs Splunk determines the source as the "Customer Name or Account ID". This causes each event to have multiple values for the field "source". Can the developers of the add-on change the name of that json field to anything other than the 4 main fields Splunk uses? source_host would be a better name for it.
TYIA,
Joe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
eegiievol
Explorer
09-02-2020
07:20 PM
Could you please help me. Is there anything else I have to modify except inputs.conf. I have trouble getting data onboard.
