Getting Data In

Is there a bug in Splunk 6 with adding an attribute of an object in data models for a JSON field name containing curly brackets?

dominicwood
Engager

I'm trying to create an object and add some auto-extracted attributes. Some field names contain curly braces because our JSON data contains array structures. As the screenshot shows, the field name is facts.authorizations{}.authorization.expiry.

When implementing a Splunk search, using this field name works perfectly fine; and this is also automatically generated in the list of attributes. However, when I select this field to be added into an attribute, Splunk generates an error message stating "Field Name cannot contain whitespace, double quotes, single quotes, curly braces or asterisks", which prevents me from adding this attribute.

I wonder if this is a bug in Splunk? Should the constraints on field name be applied to the rename field name instead of the indexed field?

Please also suggest any remedy to this problem. Thanks a lot.

alt text

1 Solution

masonmorales
Influencer

I would create a field alias, and then add the field alias to the data model as an attribute instead of the original field name. See: http://docs.splunk.com/Documentation/Splunk/6.2.5/Knowledge/Addaliasestofields

View solution in original post

masonmorales
Influencer

I would create a field alias, and then add the field alias to the data model as an attribute instead of the original field name. See: http://docs.splunk.com/Documentation/Splunk/6.2.5/Knowledge/Addaliasestofields

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...