Dashboards & Visualizations

Rename Columns not Fields

genesiusj
Builder

Hello,
Is it possible to rename a table column without renaming the field?
I have several child dashboards that I drill down to from a parent dashboard. In the parent dashboard I want to rename the columns to something more descriptive. However, all of these columns are also fields for other searches in the child dashboards.
Thanks and God bless,
Genesius

0 Karma

sandeepmakkena
Contributor
| rename Old_column as New_column_Name

I think you can just change the name, but when you pass tokens to other searches, you can pass the original name of the column as token value.
For example:
<set token=col>Old_column<set> you can use this token $col$ in your drilldown search.

Hope this helps, Thanks!

0 Karma

genesiusj
Builder

@sandeepmakkena
Just so I understand.
Although the field (column) has been renamed, and we can no longer use the original name in eval, rex, or other commands. However, the original name is still available to be used as a token which can be passed to other child dashboards, and other panels on the parent dashboard?

Thanks and God bless,
Genesius

0 Karma

jdhunter
Path Finder

See past answers submission below, he recommends using the rename command.

https://answers.splunk.com/answers/59171/changing-table-column-header-names.html

0 Karma

genesiusj
Builder

@jdhunter
Thank you.
This won't work for me. I know about the rename command. What I want to be able to do is rename the header in the table, not the field name itself.
For example.
Original field name: userId1, userId2
Both these fields are used in child dashboards. However, in the parent dashboard the column names for these two fields needs to be...
Remote Central Office User
Remote Branch Office User

I don't want to use those names as tokens for the subsequent child dashboards.

Is there a way to rename a table header AND NOT the field itself?

Thanks and God bless,
Genesius

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...