Within Splunk ES, I have two tags applied based on Event types and cannot for the life of me get it to apply when attempting to validate the data model and the data. Of all things, the only field not working is the tag field. I even made an alias for tag, which I think is pointless since the original field is called tag already. Are there any suggestions besides admitting I have lost my sanity?
My two tags were not listed in the tag whitelist. Adding them there solved the problem. Add them under
ES > CIM Setup > Intrusion Detection
and adding the two tags to the tags whitelist
My two tags were not listed in the tag whitelist. Adding them there solved the problem. Add them under
ES > CIM Setup > Intrusion Detection
and adding the two tags to the tags whitelist