From my threat intel source, we tried to forward the intelligence source to Splunk ES-> Threat Intelligence
The raw intelligence files has all the fields including the "Organisation", however in ES , it only shows a subset of the fields.
May I know how can I include the "Organisation" field in ES?