I am using KV filter to extract fields from 'remain' field , which is working good. But then I want to rename the filed 'USERNAME' which is extracted from the 'remain'
field.
When i renamed the field to 'user.name' no such field is created in elasticsearch
I am trying to map the fields in my logs , with the ECS fields. My logs contain a field 'USERNAME' which i am extracting using KV filter . I want to rename it as 'user.name' so that it populates in the SIEM app of elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.