We ingested some data from one device which is not add to network traffic datamodel by default. this device sends data in json format.
data is added to datamodel but when i use auto extracted fields and rename that field to already existed field it is still showing original name in interesting fields.
source field = data.clientaddr
dest field = src_ip
why i need this to be changed at source level because i want one search to work for all devices.
I am using tstats command in search
in interesting fields it is still showing data.clientaddr instead of src_ip
so as i said we are using datamodel with tstats and as tstat we have to use by clause and fields like All_Traffic.src_ip so if the field is not converted before this by clause it can not be used afterwards.
what i did instead, rename the field in data model and using field alies i changed the name to this field.
now we can use src_ip instead of data.clientaddr in any search without renaming it. obviously rename command is more hassel free, but as we all know a permenant solution is what evenyone needs
Hi @Nawab ,
you have two solutions:
in this way, you can use the DM fields for your searches with tstats.
This aliases should be visible both in DMs and in original data, how do you renamed them: in the DM or in the add-on.
Do it in the add-on, so you can see them in intersting fields.
Ciao.
Giuseppe