hi, is there a way to rename a splunk field but that if the field name already exists it won't get clobbered?
E.g.
let's say some events have a field called oldfield and some already have a field called newfield
I want oldfield to get renamed but if newfield exists (and I know old field won't exist if it does) then I want that to be newfield
thanks,
Instead of rename, you could use an eval to determine the value, and then just remove the oldfield.
| eval newfield=coalesce(newfield,oldfield) | fields - oldfield
Instead of rename, you could use an eval to determine the value, and then just remove the oldfield.
| eval newfield=coalesce(newfield,oldfield) | fields - oldfield
Outrageous trick! Very helpful, thank you! 😀
thanks! ..
(I used to know how to do it but I forgot)