When using kvmode=json to carve fields, when I try to create a field alias to make the fields CIM compliant, they don't appear to take. I assume there is a precedence here. Is there a way to accomplish this while still having the fields initially extracted with kvmode?
Any help would be appreciated.
Thanks,
-Bob
Are you saying, "I have complete control of the format of my logs which are in json
format and I am adding field names that are CIM-compliant
"? If so, then the only thing that could be wrong is that you're event is not fully-valid json but in that case it would not be some fields that are missing; it would be ALL fields.
Hi RD,
I did face a similar issue before, i did force some required fields, which worked in my case.
https://answers.splunk.com/answers/562805/how-to-force-to-set-certain-fields-host-and-source.html