<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Datamodel field rename in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693944#M236054</link>
    <description>&lt;P&gt;We ingested some data from one device which is not add to network traffic datamodel by default. this device sends data in json format.&lt;/P&gt;&lt;P&gt;data is added to datamodel but when i use auto extracted fields and rename that field to already existed field it is still showing original name in interesting fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source field = data.clientaddr&lt;/P&gt;&lt;P&gt;dest field = src_ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why i need this to be changed at source level because i want one search to work for all devices.&lt;/P&gt;&lt;P&gt;I am using tstats command in search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in&amp;nbsp;interesting fields it is still showing data.clientaddr instead of src_ip&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 09:25:48 GMT</pubDate>
    <dc:creator>Nawab</dc:creator>
    <dc:date>2024-07-22T09:25:48Z</dc:date>
    <item>
      <title>Datamodel field rename</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693944#M236054</link>
      <description>&lt;P&gt;We ingested some data from one device which is not add to network traffic datamodel by default. this device sends data in json format.&lt;/P&gt;&lt;P&gt;data is added to datamodel but when i use auto extracted fields and rename that field to already existed field it is still showing original name in interesting fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source field = data.clientaddr&lt;/P&gt;&lt;P&gt;dest field = src_ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why i need this to be changed at source level because i want one search to work for all devices.&lt;/P&gt;&lt;P&gt;I am using tstats command in search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in&amp;nbsp;interesting fields it is still showing data.clientaddr instead of src_ip&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 09:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693944#M236054</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2024-07-22T09:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Datamodel field rename</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693946#M236055</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244855"&gt;@Nawab&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you have two solutions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;add new fields to you Data Model, I don't like this solution:&lt;/LI&gt;&lt;LI&gt;rename your fields to insert them in the DM fields, this is the prefereable solution.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;in this way, you can use the DM fields for your searches with tstats.&lt;/P&gt;&lt;P&gt;This aliases should be visible both in DMs and in original data, how do you renamed them: in the DM or in the add-on.&lt;/P&gt;&lt;P&gt;Do it in the add-on, so you can see them in intersting fields.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 09:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693946#M236055</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-07-22T09:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Datamodel field rename</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693947#M236056</link>
      <description>&lt;P&gt;so as i said we are using datamodel with tstats and as tstat we have to use &lt;STRONG&gt;by&lt;/STRONG&gt; clause and fields like &lt;STRONG&gt;&lt;SPAN class=""&gt;All_Traffic.src_ip&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;so if the field is not converted before this&amp;nbsp;&lt;STRONG&gt;by&amp;nbsp;&lt;/STRONG&gt;clause it can not be used afterwards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;what i did instead, rename the field in data model and using field alies i changed the name to this field.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;now we can use src_ip instead of data.clientaddr in any search without renaming it. obviously rename command is more hassel free, but as we all know a permenant solution is what evenyone needs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 09:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Datamodel-field-rename/m-p/693947#M236056</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2024-07-22T09:42:11Z</dc:date>
    </item>
  </channel>
</rss>

