Hello
I have pre-parsed information coming into my Splunk instance for CISCO:ASA. I'm wondering why the field "direction" has a value of "inbound" showing up as "inbound" and "Inbound". How can I combine the two? Do I want to combine the two?....seems like it...
Thanks
Tim
There are a lot of ways to do that, if you want. For example...
[yourstanzaname]
SOURCE_KEY = direction
REGEX = (?i)inbound
DEST_KEY = direction
FORMAT = inbound