Splunk Enterprise Security

Splunk Enterprise Security Threat Intelligence does not have field "Organization"

tan_junyuan
Engager

From my threat intel source, we tried to forward the intelligence source to Splunk ES-> Threat Intelligence

The raw intelligence files has all the fields including the "Organisation", however in ES , it only shows a subset of the fields.

May I know how can I include the "Organisation" field in ES?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...