All Apps and Add-ons

Sophos App - JSON fields renaming

JScordo
Path Finder

After installing the add-on and getting data into my environment from the Sophos Add-On For Splunk (https://splunkbase.splunk.com/app/4096/) I noticed that the json comes with a field named "source" which causes issues since when setting the inputs Splunk determines the source as the "Customer Name or Account ID". This causes each event to have multiple values for the field "source". Can the developers of the add-on change the name of that json field to anything other than the 4 main fields Splunk uses? source_host would be a better name for it.

TYIA,
Joe

0 Karma

eegiievol
Explorer

Could you please help me. Is there anything else I have to modify except inputs.conf. I have trouble getting data onboard. 

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...