Getting Data In

Receiving an error while using the mvexpand command (does not exist in the data)

super_saiyan
Communicator

Hi everyone,

currently, i am trying to expand one of the multiple field values but i am getting the result with the below error.
Field 'deployment' does not exist in the data.

index=json
|rex mode=sed "s/.*-\s//g"
|spath
|rename ops{}.steps{}.steps{}.address{}.deployment as deployment 
|mvexpand deployment
|mvexpand operation
|table deployment

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Put the field name in double quotes (usually it is single quotes for field names but rename seems to operate differently)

|rename "ops{}.steps{}.steps{}.address{}.deployment" as deployment 
0 Karma

super_saiyan
Communicator

anyone ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you don't have the deployment field, what fields do you have?

0 Karma

super_saiyan
Communicator

Hi, I have shared the logs with you in DM

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@super_saiyan 

Can you please share some sample events?

Meanwhile, you can try this rename as well. 

| rename "ops.steps.steps.address.deployment" as deployment

 

KV

0 Karma

super_saiyan
Communicator

Thanks much @kamlesh_vaghela 
I have shared the logs in DM, please check

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...