Splunk Search

How can er rename the default field count ?

rakesh_498115
Motivator

Hi..

I am using the top command . Now i want to rename the count field that comes default with the top command . how can i do tat ??

I tried like this..

sourcetype="x" | top eventtype | rename count as ReqCount

But this is not workin..Please Help

Tags (1)
0 Karma
1 Solution

MHibbin
Influencer

How odd! ... similar searches work fine for me.

Do you receive the desired results? - only the column header does not change?

I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)

...Probably no help at all, just thought I would say/ask something..

🙂

View solution in original post

0 Karma

MHibbin
Influencer

How odd! ... similar searches work fine for me.

Do you receive the desired results? - only the column header does not change?

I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)

...Probably no help at all, just thought I would say/ask something..

🙂

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...