I believe we would use field aliases to align the fields sent by Heroku with the CIM fields for Web.
This would benefit the Enterprise Security product which leans on the Splunk common information models. It would enable the inclusion of Heroku request logs in any evaluations that the SEIM product runs.
See https://docs.splunk.com/Documentation/CIM/5.0.1/User/Web.
I believe we would use field aliases to align the fields sent by Heroku with the CIM fields for Web.
This would benefit the Enterprise Security product which leans on the Splunk common information models. It would enable the inclusion of Heroku request logs in any evaluations that the SEIM product runs.