<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field Aliases in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112736#M29630</link>
    <description>&lt;P&gt;I tried this out, but dc(c) is always equal to dc(a).&lt;BR /&gt;
The fields A &amp;amp; B can both appear in one event. So I think that's why this command is just using the users of the field A.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2014 14:56:38 GMT</pubDate>
    <dc:creator>HeinzWaescher</dc:creator>
    <dc:date>2014-01-15T14:56:38Z</dc:date>
    <item>
      <title>Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112732#M29626</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to configure some field aliases. I want to add an alias C for the fields A &amp;amp; B. &lt;BR /&gt;
I've done this in the settings, but in the search it only works for field A. Is it not possible to set one alias for 2 different fields?&lt;/P&gt;

&lt;P&gt;Best &lt;BR /&gt;
Heinz&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2014 13:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112732#M29626</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-14T13:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112733#M29627</link>
      <description>&lt;P&gt;What is the value of C supposed to be if both A and B exist?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2014 15:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112733#M29627</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-14T15:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112734#M29628</link>
      <description>&lt;P&gt;Users can appear in both fields. I would like to have a way to create stats about distinct users. That's why I wanted to set two aliases:&lt;/P&gt;

&lt;P&gt;A=C&lt;BR /&gt;
B=C&lt;/P&gt;

&lt;P&gt;Then I would have to deal only with one field (C) in the search.&lt;/P&gt;

&lt;P&gt;PS: Next to that, I don't know how to handle a search for distinct user over 2 fields &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 14:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112734#M29628</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-15T14:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112735#M29629</link>
      <description>&lt;P&gt;You could do this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval C = coalesce(A, B) | stats dc(C)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;"Use A if exists, else use B". That can be stored in a calculated field if you like.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 14:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112735#M29629</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-15T14:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112736#M29630</link>
      <description>&lt;P&gt;I tried this out, but dc(c) is always equal to dc(a).&lt;BR /&gt;
The fields A &amp;amp; B can both appear in one event. So I think that's why this command is just using the users of the field A.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 14:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112736#M29630</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-15T14:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112737#M29631</link>
      <description>&lt;P&gt;If A and B exist in one event then my C will eval to A.&lt;/P&gt;

&lt;P&gt;What should the value of C be in this case? (See my comment on your question)&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 15:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112737#M29631</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-15T15:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112738#M29632</link>
      <description>&lt;P&gt;I thought I can collect all users from A &amp;amp; B in this field and use dc(C) to get the total distinct usercount.&lt;/P&gt;

&lt;P&gt;But it doesn't make sense via an alias, because there would be more than 1 value for the field C in each event?! &lt;/P&gt;

&lt;P&gt;In the end, I'm just looking for way to dc(users). These users can appear in the fields A &amp;amp; B.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 15:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112738#M29632</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-15T15:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112739#M29633</link>
      <description>&lt;P&gt;That's beyond an alias. You basically want to merge A and B into a multi-value field.&lt;/P&gt;

&lt;P&gt;You can eval your way there though, like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal | eval sst = source."###".sourcetype | makemv sst delim="###" | stats dc(source) dc(sourcetype) dc(sst)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Imagine source is A, sourcetype is B, and sst is C. That eval should be includeable in a calculated field, but probably not the makemv. You can go macro of course.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 16:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112739#M29633</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-15T16:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112740#M29634</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;

&lt;P&gt;ich wechsel mal die Sprache, macht's etwas einfacher &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Deinen Ansatz kann ich soweit nachvollziehen, allerdings scheint dc(sst) nicht wie gewünscht zu funktionieren. Soll hierbei jedes einzelne Element der multivalue fields gezählt werden?&lt;/P&gt;

&lt;P&gt;Meine Suche:&lt;/P&gt;

&lt;P&gt;| eval C=A."###".B | makemv C delim="###" | stats dc(A), dc(B), dc(C)&lt;/P&gt;

&lt;P&gt;Außerdem ist "sst" oft leer.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 12:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112740#M29634</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-16T12:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112741#M29635</link>
      <description>&lt;P&gt;Das ist der Plan. Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats count as foo | eval foo = "1-1,2-3,3-5" | makemv foo delim="," | mvexpand foo | makemv foo delim="-" | appendpipe [stats dc(foo)]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Result:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;foo   dc(foo)
1
1

2
3

3
5

.     4
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;dc(foo)&lt;/CODE&gt; ist korrekt, denn foo enthält 1,2,3,5 - also distinct count = 4.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 12:32:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112741#M29635</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-16T12:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112742#M29636</link>
      <description>&lt;P&gt;Hast recht, die Zählung ist richtig. Ich habe mir das erzeugte "foo" (oder C in meinem Beispiel) Feld exportiert und extern gezählt. &lt;BR /&gt;
Irgendetwas mache ich aber noch falsch, bzw. die Einträge in "foo" (C) sind nicht zielführend. Das Ergebniss dc(foo) (bzw. dc(c)) ist geringer als dc(A) und auch geringer als dc(B). Das darf ja nicht sein.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 13:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112742#M29636</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-16T13:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112743#M29637</link>
      <description>&lt;P&gt;&lt;CODE&gt;dc(C) &amp;lt; dc(A)&lt;/CODE&gt; darf in der Tat nicht sein - aber da läuft vorher was falsch, vermutlich beim Befüllen von C.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 13:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112743#M29637</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-16T13:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112744#M29638</link>
      <description>&lt;P&gt;Genau, ich habe es mal überprüft mit:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...| search A=* AND B=* | eval sst=A."###".B | table sst
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Einige Ergebnisfelder sehen so aus: 26828###15624 &lt;BR /&gt;
Andere hingegen sind leer, obwohl sie es nicht sein dürften.&lt;/P&gt;

&lt;P&gt;Es scheinen die Felder leer zu sein, wenn im Event mehrere Male das Feld A oder mehrere Male das Feld B auftritt.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 13:28:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112744#M29638</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-16T13:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112745#M29639</link>
      <description>&lt;P&gt;Na klar - wenn A oder B multi-value fields sind, geht die Stringkonkatenation aus meinem Beispiel nicht.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 14:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112745#M29639</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-01-16T14:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Field Aliases</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112746#M29640</link>
      <description>&lt;P&gt;Ich glaube um das Problem zu umgehen funktionert folgendes:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval A_joined = mvjoin(A, ",")
| eval B_joined = mvjoin(B, ",")
| eval C = A_joined + "," + B_joined
| makemv delim="," C | stats dc(C), dc(A), dc(B)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sieht von den Ergebnissen her auf den ersten Blick besser aus. Muss ich aber noch in ein paar Richtungen testen.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2014 15:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Aliases/m-p/112746#M29640</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-01-16T15:16:00Z</dc:date>
    </item>
  </channel>
</rss>

