I have various indexes that have different field name re: destination IPs. Would the best way to have all destination IP fields match Optiv's dest_ip involve using aliases for the various destination IP field names in the indexes?
Thx
You need the Common Information Model
:
http://docs.splunk.com/Documentation/CIM/4.8.0/User/Overview
You need the Common Information Model
:
http://docs.splunk.com/Documentation/CIM/4.8.0/User/Overview
Thx - reviewing the CIM documentation to implement