There are several overlapping field aliases causing inconsistent issues.
I recommend the following changes.
Before:
FIELDALIAS-cisco-ise-user_name-as-UserName = User_Name AS UserName
After:
FIELDALIAS-cisco-ise-user_name-as-UserName = User_Name AS user
The UserName field is used in part of the ISE log services, and is being overwritten inconsistently with blank data.
I recommend the following changes.
Before:
FIELDALIAS-cisco-ise-user_name-as-UserName = User_Name AS UserName
After:
FIELDALIAS-cisco-ise-user_name-as-UserName = User_Name AS user
I recommend the following changes.
Before:
FIELDALIAS-cisco-ise-user_name-as-UserName = User_Name AS UserName
After:
FIELDALIAS-cisco-ise-user_name-as-UserName = User_Name AS user
Hi @stboch
Thanks for sharing this tip on Splunk Answers for the rest of the community. Could you actually post the solution below in the "Enter your answer here..." box? We can then accept the answer to resolve the post so this question displays as having a working solution.
I copied the information into an answer