All Journald fields end up in the extracted_fields.

https://cloud.google.com/chronicle/docs/ingestion/parser-list/journald-changelog
All Journald fields end up in the extracted_fields.

https://cloud.google.com/chronicle/docs/ingestion/parser-list/journald-changelog
Best answer by cmmartin_google
A parser updated was recently added and is expected to start rolling out from the 7th October onwards that will normalize those JOURNALD added fields.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.