Getting Data In

Normalize feed before indexing

Anto
Explorer

Is possible to rename values of feeds? i am going to explain it better:

I have open source feeds but some values of them are written in different form, for example, i am going to group all malware names under the same field but i have this trouble:

Malware Name

NjRat command & control
NjRat
Njrat
NJraat
Njratt c&c

 

Is possible to modify them at indexing time under the same name NjRat so when i am going to analyze it i have no problem and they are all grouped? 

Thanks in advance

Labels (3)
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...