i have corelight events which has id.orig_h ,id.resp_h etc fields , but when i try to rename them using eval src_ip=id.orig_h… it doesnt work , the RENAME fucntion works though, I dont want to use rename because i dont want to lose original fields , i also cant use corelight pack because it is also using rename , how can i rename without losing original field???
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
