Hi @mayurr98, I tried out a new props that looks like it's getting the fields to ingest correctly - transforms.conf
[cs_srctype]
CLEAN_KEYS = 0
DELIMS = ,
FIELDS = action,category,dest,file_name,file_path,severity,severity_id,signature,signature_id,vendor_product
props.conf
[cs_srctype]
KV_MODE = none
REPORT-cs_srctype = cs_srctype
SEDCMD=s/^((?:[^,]+,){4}[^,]+)(?<=\\),/\1\\,/ I've only added one additional line in the props - a sedcmd to add an escape to any trailing slash in the file_path segment. With that config set up, the data is ingested with the correct vendor_product field: Cheers, Daniel
... View more