Deployment Architecture

Why the error when upgrade Splunk from 7.3.x to 8.1.5 on DMC Search Activity?

dm1
Contributor

Newly upgraded Splunk to 8.1.5 from 7.3.x and seeing the below error message on DMC Search Activity:Instance

 

Multiple renames to field 'Type' detected. Only the last one will appear, and previous 'from' fields will be dropped.

 

Any ideas or suggestions on how to fix this ?

 

Labels (2)
0 Karma

Keysofsandiego
Path Finder

You can drill down into the search, and just remove the last rename. 
delete this  -  search_props.type as "Type"

If you take that off it will work without error. 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...