Hmm, I'm not so sure. Wouldn't normalizing the data to the Splunk Common Information Model be important too? That would help ensure consistency and compatibility with ES.
This question is a bit tricky, but I think the key is understanding the Data Model and how it interacts with Elasticsearch (ES). If the raw data isn't properly extracted and normalized, it won't be usable by the Data Model or ES.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Glenna
17 days agoIzetta
19 days agoSalome
20 days agoBuddy
21 days agoLeonora
23 days agoFrancine
25 days ago