<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Applying many field aliases to many sourcetypes in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375382#M3184</link>
    <description>&lt;P&gt;Yes, you can do this by adding regex to a stanza. (NOT SUPPORTED I believe)&lt;/P&gt;

&lt;P&gt;I’ve seen an example like this;&lt;/P&gt;

&lt;P&gt;Let’s say you have 3 sourcetypes&lt;/P&gt;

&lt;P&gt;acme:users&lt;BR /&gt;
acme:logins&lt;BR /&gt;
acme:sessions&lt;/P&gt;

&lt;P&gt;Stanza [acme:&lt;EM&gt;] will NOT work.&lt;BR /&gt;
But regexed stanza [(?::){0}acme:&lt;/EM&gt;] WILL work.&lt;/P&gt;

&lt;P&gt;I have not tested this myself...&lt;/P&gt;</description>
    <pubDate>Fri, 23 Mar 2018 21:34:41 GMT</pubDate>
    <dc:creator>Azeemering</dc:creator>
    <dc:date>2018-03-23T21:34:41Z</dc:date>
    <item>
      <title>Applying many field aliases to many sourcetypes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375381#M3183</link>
      <description>&lt;P&gt;I'm trying to find a way to create multiple field aliases across many sourcetypes. Much of our data being fed into splunk is done through JSON format, so field names are entire paths - &lt;CODE&gt;something.something.moreannoyingthings&lt;/CODE&gt;. While it doesn't directly affect querying, I wanted to set up multiple field aliases to make our users lives easier.&lt;/P&gt;

&lt;P&gt;However, we have a variety of sourcetypes that, while containing similar JSON data, are split for good reasons. As a result, any field alias I create would have to be duplicated many times, and I want to create many. In addition, any time we create a new sourcetype, I would need to retread the same work.&lt;/P&gt;

&lt;P&gt;Is there a way to apply some sort of regex to sourcetypes to be able to apply a given field alias across many sourcetypes? Even something simple like &lt;CODE&gt;*-prod&lt;/CODE&gt;. &lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 20:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375381#M3183</guid>
      <dc:creator>brajaram</dc:creator>
      <dc:date>2018-03-23T20:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Applying many field aliases to many sourcetypes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375382#M3184</link>
      <description>&lt;P&gt;Yes, you can do this by adding regex to a stanza. (NOT SUPPORTED I believe)&lt;/P&gt;

&lt;P&gt;I’ve seen an example like this;&lt;/P&gt;

&lt;P&gt;Let’s say you have 3 sourcetypes&lt;/P&gt;

&lt;P&gt;acme:users&lt;BR /&gt;
acme:logins&lt;BR /&gt;
acme:sessions&lt;/P&gt;

&lt;P&gt;Stanza [acme:&lt;EM&gt;] will NOT work.&lt;BR /&gt;
But regexed stanza [(?::){0}acme:&lt;/EM&gt;] WILL work.&lt;/P&gt;

&lt;P&gt;I have not tested this myself...&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 21:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375382#M3184</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2018-03-23T21:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Applying many field aliases to many sourcetypes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375383#M3185</link>
      <description>&lt;P&gt;I assume this needs to be defined in props.conf? We use splunk web so I assume I can't do this through the web UI?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 21:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375383#M3185</guid>
      <dc:creator>brajaram</dc:creator>
      <dc:date>2018-03-23T21:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Applying many field aliases to many sourcetypes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375384#M3186</link>
      <description>&lt;P&gt;We had a similar thread at &lt;A href="https://answers.splunk.com/answers/591288/how-can-we-apply-truncate-across-many-sourcetypes.html"&gt;How can we apply TRUNCATE across many sourcetypes?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Mar 2018 22:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Applying-many-field-aliases-to-many-sourcetypes/m-p/375384#M3186</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-03-24T22:05:51Z</dc:date>
    </item>
  </channel>
</rss>

