How to Convert array fields from beats to compatible array fields of Splunk HEC input viai Logstash

This is the logstash output to splunk HEC input event endpoint.

"fields":"{\"netcool_fields_community\":\"AGENT_HB\",\"metric_name:status\":1}"}"

I am not sure what is failing . Events are not getting indexed to metric index.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.