I am using dbquery to join two tables and display the results. Unfortunately, both tables use the column "NAME"
I want to use the AS function in SQL to rename the column from one DB so that it shows correctly in splunk like this
| dbquery "MAIN" "SELECT m.NAME AS HOST_NAME, s.ID AS GROUP_ID, s.NAME AS GROUP_NAME FROM MAIN.MACHINE m JOIN SYS.MUID s on m.uid=s.uid"
the "AS" clause in the SQL is not renaming the field, so splunk picks the first NAME field it sees and does not show the other NAME field in the row.
This should be a simple SQL command, but it doesn't seem to be working with Splunk DB Connect?
no idea. Well, three ideas: