Hi Elastic Team,
I have certain fields which we use in Linux logs and can you please let me know what would be the Elastic common schema(ECS) name for those fields and how you define the ECS name for those fields ??
Fields : timestamp, ppid, msg, address, hostname, terminal, algo, comm, success, server etc
Example : we had src_ip defined in one of our logs and elastic common schema accepts source.ip how this is defined ?
please look into the section Example 2: Search from the above link where you can find the details of src_ip example which I mentioned about!