<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Aliases not working in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665980#M9781</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am having an issue creating an alias simply going from DestinationPort to dest_port for SysMon EventID 3&lt;/P&gt;
&lt;P&gt;I have tested:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=my_index source=Sysmon

| eval destinationPort=dest_port&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen in Splunk TA Sysmon that there is FIELDALIAS-dest_port=DestinationPort AS dest_port&lt;/P&gt;
&lt;P&gt;but still cannot convert DestinationPort to dest_port at Search time.&lt;/P&gt;
&lt;P&gt;Any suggestions, please? There are no other apps contradicting the precedence.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 14:09:22 GMT</pubDate>
    <dc:creator>DanAlexander</dc:creator>
    <dc:date>2023-10-24T14:09:22Z</dc:date>
    <item>
      <title>Aliases not working</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665980#M9781</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I am having an issue creating an alias simply going from DestinationPort to dest_port for SysMon EventID 3&lt;/P&gt;
&lt;P&gt;I have tested:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=my_index source=Sysmon

| eval destinationPort=dest_port&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen in Splunk TA Sysmon that there is FIELDALIAS-dest_port=DestinationPort AS dest_port&lt;/P&gt;
&lt;P&gt;but still cannot convert DestinationPort to dest_port at Search time.&lt;/P&gt;
&lt;P&gt;Any suggestions, please? There are no other apps contradicting the precedence.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 14:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665980#M9781</guid>
      <dc:creator>DanAlexander</dc:creator>
      <dc:date>2023-10-24T14:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Aliases not working</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665996#M9782</link>
      <description>&lt;P&gt;Make sure the sourcetype on your data matches that for the FIELDALIAS.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 12:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665996#M9782</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-24T12:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Aliases not working</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665998#M9783</link>
      <description>&lt;P&gt;And remember that for search-time operations it's important if you have enough permissions for the app (that should not typically be the issue here but it's worth checking out if all else fails)&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 13:09:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Aliases-not-working/m-p/665998#M9783</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-24T13:09:10Z</dc:date>
    </item>
  </channel>
</rss>

