Getting Data In

Receiving an error while using the mvexpand command (does not exist in the data)

super_saiyan
Communicator

Hi everyone,

currently, i am trying to expand one of the multiple field values but i am getting the result with the below error.
Field 'deployment' does not exist in the data.

index=json
|rex mode=sed "s/.*-\s//g"
|spath
|rename ops{}.steps{}.steps{}.address{}.deployment as deployment 
|mvexpand deployment
|mvexpand operation
|table deployment

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Put the field name in double quotes (usually it is single quotes for field names but rename seems to operate differently)

|rename "ops{}.steps{}.steps{}.address{}.deployment" as deployment 
0 Karma

super_saiyan
Communicator

anyone ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you don't have the deployment field, what fields do you have?

0 Karma

super_saiyan
Communicator

Hi, I have shared the logs with you in DM

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@super_saiyan 

Can you please share some sample events?

Meanwhile, you can try this rename as well. 

| rename "ops.steps.steps.address.deployment" as deployment

 

KV

0 Karma

super_saiyan
Communicator

Thanks much @kamlesh_vaghela 
I have shared the logs in DM, please check

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...