Cribl 利用表向event 中插入相应的字段-example-01

先看文档: Ingest-Time Lookups | Cribl Docs

Enriching Data in Motion

To enrich events with new fields from external sources (such as .csv files), we use Cribl Stream’s out-of-the-box Lookup Function. Ingestion-time lookups are not only great for normalizing field names and values, but also ideal for use cases where:

  • Fa

你可能感兴趣的:(splunk,splunk,cribl,CSV,event,字段)