Hi..
I am using the top command . Now i want to rename the count field that comes default with the top command . how can i do tat ??
I tried like this..
sourcetype="x" | top eventtype | rename count as ReqCount
But this is not workin..Please Help
How odd! ... similar searches work fine for me.
Do you receive the desired results? - only the column header does not change?
I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)
...Probably no help at all, just thought I would say/ask something..
🙂
How odd! ... similar searches work fine for me.
Do you receive the desired results? - only the column header does not change?
I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)
...Probably no help at all, just thought I would say/ask something..
🙂