Hi guys,
Someone can enlighthen when using log analyzer what is the difference of parameter "SourceIP" and "src_ip"?
Thanks.
It depends on the log in which you are ingesting. Depending on the log it might tag the source IP as one or the other depending on the log format/content. Typically they mean the same thing and it is beneficial in Splunk to use the Common Information Model to make them alike. See http://docs.splunk.com/Documentation/CIM/4.9.1 for reference. What log or logs are you seeing these fields in? If you have additional questions, could you post a sample event?