<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rename field with * in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710195#M239947</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the dropdown ALL value = *&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="secure_0-1738186419172.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34293iA4065F636416D483/image-size/medium?v=v2&amp;amp;px=400" role="button" title="secure_0-1738186419172.png" alt="secure_0-1738186419172.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;in the query&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="secure_2-1738186509556.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34295iA58342D59D19DA49/image-size/medium?v=v2&amp;amp;px=400" role="button" title="secure_2-1738186509556.png" alt="secure_2-1738186509556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;so when selected all it comes as server_*_count&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2025 21:35:47 GMT</pubDate>
    <dc:creator>secure</dc:creator>
    <dc:date>2025-01-29T21:35:47Z</dc:date>
    <item>
      <title>rename field with *</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710188#M239944</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a field with name&amp;nbsp;&lt;/P&gt;&lt;P&gt;server_*_count. the * is coming from an input dropdown ALL where value is *&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can i rename it to server_ALL_count&lt;/P&gt;&lt;P&gt;|rename server_*_count as&amp;nbsp;server_ALL_count&lt;BR /&gt;&lt;BR /&gt;its giving me an error cannot be renamed because of asterix (wildcard)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 21:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710188#M239944</guid>
      <dc:creator>secure</dc:creator>
      <dc:date>2025-01-29T21:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: rename field with *</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710191#M239946</link>
      <description>&lt;P&gt;You can't rename it like that - how does that field exist? Is it actually in the data or is it created somehow.&lt;/P&gt;&lt;P&gt;Can you post the dropdown where that field is created?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 21:29:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710191#M239946</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2025-01-29T21:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: rename field with *</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710195#M239947</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the dropdown ALL value = *&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="secure_0-1738186419172.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34293iA4065F636416D483/image-size/medium?v=v2&amp;amp;px=400" role="button" title="secure_0-1738186419172.png" alt="secure_0-1738186419172.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;in the query&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="secure_2-1738186509556.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34295iA58342D59D19DA49/image-size/medium?v=v2&amp;amp;px=400" role="button" title="secure_2-1738186509556.png" alt="secure_2-1738186509556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;so when selected all it comes as server_*_count&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 21:35:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710195#M239947</guid>
      <dc:creator>secure</dc:creator>
      <dc:date>2025-01-29T21:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: rename field with *</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710200#M239950</link>
      <description>&lt;P&gt;OK, so it's getting created in the stats command. So don't use that technique. Do something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats dc(hostname) as server_count
| eval n=if($env|s$="*", "ALL", $env|s$)
| eval server_{n}_count=server_count
| fields - server_count&lt;/LI-CODE&gt;&lt;P&gt;but do you really need the $env$ in the field name? Is this dashboard studio - you can probably assign an additional token $env_name$ based on the selected NAME of the environment rather than the token value. I'm not familiar enough with DS to say how to do this, but you can then use $env$ as the search constraint and $env_name$ as the server name.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 21:43:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710200#M239950</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2025-01-29T21:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: rename field with *</title>
      <link>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710217#M239959</link>
      <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;says&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;SPAN&gt;but do you really need the $env$ in the field name?&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Wouldn't&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats dc(hostname) by host_environment&lt;/LI-CODE&gt;&lt;P&gt;make more sense in a dashboard?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 03:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/rename-field-with/m-p/710217#M239959</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2025-01-30T03:46:26Z</dc:date>
    </item>
  </channel>
</rss>

