Splunk Enterprise Security… there's a lot of SPL out there that leverages the date_ fields that the TAs on splunk HFs create when parsing time. How is everyone dealing with lack of these fields, and aliasing to CIM etc by Splunk TAs when leveraging cribl stream?
Question
Handling the missing date_ fields for Splunk Enterprise Security
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.


