Knowledge Management

KVstore field Aliase

florianhh
Explorer

Gooood Morning 🙂

I need some advice, we have several sources of Information about our Company assets, i know not ideal but better then dont know any.

So i wrote a script thats collects everything from these Asset sources and writes the Info to a big KV Store. (1.5GB) on the Splunk-ES SH.

The script does that every 6h. 

No i want to add these Info to the Splunk ES Asset- und Identitäts-Management.

How do i aliase a kvstore field name so its CIM compliance with the required fieldnames as stated here. https://docs.splunk.com/ ?

I thought about fieldaliases in a props.conf as per normal datasources.

But im not sure to use the collection name as a source in the stanza? 

 

 

 

[source::ipam_assets_collection]
FIELDALIAS-asset_ip = Address AS ip

 

 

 

 
Is there a better way?
Labels (3)
0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...