Hmm, I'm not so sure. Wouldn't normalizing the data to the Splunk Common Information Model be important too? That would help ensure consistency and compatibility with ES.
This question is a bit tricky, but I think the key is understanding the Data Model and how it interacts with Elasticsearch (ES). If the raw data isn't properly extracted and normalized, it won't be usable by the Data Model or ES.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Lashon
9 months agoZona
10 months agoJuan
10 months agoMike
10 months agoGlenna
11 months agoIzetta
11 months agoSalome
11 months agoAdell
9 months agoClare
9 months agoNorah
9 months agoDelsie
9 months agoBuddy
11 months agoLeonora
11 months agoFrancine
11 months ago