Splunk Enterprise Security

Update default/props.conf with TA-eStreamer

lakshman239
SplunkTrust
SplunkTrust

Hello @douglashurd - Could you pls review default/props.conf as its reusing same name [FIELDALIAS-eStreamer_category] twice within the [cisco:estreamer:data] stanza in the latest version and update to have unique names in future versions? I am using 3.5.3

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!