Dashboards & Visualizations

How come our field aliases are not working in Splunk?

merp96
Path Finder

Hi

I have created a field alias stanza in props in the heavy forwarder, but I'm not able to see the fields in the search head.

The below is the stanza.

[sourcetype1]
FIELDALIAS-userid = user AS Emp_ID name AS Emp_Name

Not sure what I am missing here.

0 Karma
1 Solution

HiroshiSatoh
Champion

The field alias must be present in the search head( OR indexer) as it will be referenced at the time of the search.

View solution in original post

0 Karma

HiroshiSatoh
Champion

The field alias must be present in the search head( OR indexer) as it will be referenced at the time of the search.

0 Karma

merp96
Path Finder

Thanks @HiroshiSatoh . Will try in indexer.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...