I'd like to implement some basic searches for virtualization monitoring without getting caught up in the differences between sourcetypes and field names.
Are there any basic searches that provide virtualization monitoring without me having to deal with the complexities of the sourcetype differences? Something akin to the Performance Model of the Common Information Model, perhaps?
The answer for this question has been distributed to the following posts:
The answer for this question has been distributed to the following posts:
Replaced the answer with its new homes.
Added guidance on Alerts