Skip to main content
Panther Knowledge Base

Is it possible to extract a nested field while ingesting logs to Panther?


 Is it possible to extract a field and make that a column at ingestion time, even if it is nested? I want to make it a separate schema field.


 No, that is not possible. If a field is nested in your data, it would need to be nested in the schema.

If you are looking to normalize your data to create detections for multiple log types, see the documentation on Panther Data Models for more information.