Knowledge Management

Best way to rename destination IP fields for Optiv?

jwalzerpitt
Influencer

I have various indexes that have different field name re: destination IPs. Would the best way to have all destination IP fields match Optiv's dest_ip involve using aliases for the various destination IP field names in the indexes?

Thx

0 Karma
1 Solution

woodcock
Esteemed Legend

woodcock
Esteemed Legend

You need the Common Information Model:
http://docs.splunk.com/Documentation/CIM/4.8.0/User/Overview

jwalzerpitt
Influencer

Thx - reviewing the CIM documentation to implement

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...