I am new in Splunking ,
I need to understand few thing ,could anyone please answer the questions :
1.) How to make list of sourcetype and eventtype that need to be fixed to allow for proper data model
2.) How to identify incorrect Aliased /extracted fields ?
3.)How to Determine the sourcetype associated with incorrect /unknown fields
4.) how to identified incorrect /unknown fields from datamodel
what are the steps to fix, Sorry these are common question but being new I need to create report for it !!
Thank in Advance !!!
There are several ways to do field extraction. Use
FORMAT in transforms.conf; use
REPORT in props.conf; use
extract in search.