Good morning all, I am reading docs on how to create sourcetypes for metrics but none go into how to just use fields instead of regex. I am using fluentbit to send metrics to HEC (and it works perfectly) in JSON format.
How do I use the existing fields to rewrite the sourcetype as metrics?
I included a screenshot of what the events look like.
Can’t you define the sourcetype when you setup the HEC token?
Would you want to change the sourcetype there?
There is a sourcetype rename feature in the settings drop down under fields I believe.
When metrics are involved it's more than just defining the sourcetype. Standard fields need to be defined to play well with metrics store.
http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MOverview
Ok so you don’t want to “rewrite the sourcetype as metrics”...
This was somewhere on the link you gave, does it make sense?
http://docs.splunk.com/Documentation/Splunk/7.2.1/Metrics/L2MConfiguration