Skip to main content
Panther Knowledge Base

Is it possible to extract a nested field while ingesting logs to Panther?

QUESTION

 Is it possible to extract a field and make that a column at ingestion time, even if it is nested? I want to make it a separate schema field.

ANSWER

 No, that is not possible. If a field is nested in your data, it would need to be nested in the schema.

If you are looking to normalize your data to create detections for multiple log types, see the documentation on Panther Data Models for more information.

 

  • Was this article helpful?