Is there any way to rename fields for by getting value from different source?
For example in my log file i have user=100, and i have table or just a text file, where i spcify 100=Jhon Doe. So i can repleace 100 with Jhon Doe in my reports?
Its called a lookup, and you need to generate your list first as a csv file. (outputlookup is your friend)
then call the lookup command at search time to to add new fields, or rename fields values..
see http://docs.splunk.com/Documentation/Splunk/6.0/SearchReference/Lookup
http://docs.splunk.com/Documentation/Splunk/6.0/Search/Useexternalfieldlookups
Its called a lookup, and you need to generate your list first as a csv file. (outputlookup is your friend)
then call the lookup command at search time to to add new fields, or rename fields values..
see http://docs.splunk.com/Documentation/Splunk/6.0/SearchReference/Lookup
http://docs.splunk.com/Documentation/Splunk/6.0/Search/Useexternalfieldlookups
Thank you good man.