Skip to content
Discussion options

You must be logged in to vote

Unless I am misunderstanding your question, I think this is more a question that needs to be directed at Chronicle. I believe you will need to setup a parser there that can parse your logs. It looks like this could be a useful starting point.

There are things you can do in Vector using the Remap transform to modify your data if you need to structure it in a way that can make it easier to parse in Chronicle. That will very much depend on what the current structure is, if you have any questions after reading the docs, please ask.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by TommySarkissian
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants