Hello
Do field values have to be consistent for ES or doesn't it matter? So in the wineventlog if src is sometimes the IP and other times the fqdn does ES care? Same with the user field, if sometimes the field value is bob@domain or domain-bob or bob$ does it matter?
Thanks
R00ster
CIM focuses on field names and completely ignores the values.
As for whether or not ES cares, that depends on how the field is used. Attempting to correlate source addresses in events will be a challenge if some events contain IP addresses and others contain FQDNs, for example.
CIM focuses on field names and completely ignores the values.
As for whether or not ES cares, that depends on how the field is used. Attempting to correlate source addresses in events will be a challenge if some events contain IP addresses and others contain FQDNs, for example.