Getting Data In

Receiving an error while using the mvexpand command (does not exist in the data)

super_saiyan
Communicator

Hi everyone,

currently, i am trying to expand one of the multiple field values but i am getting the result with the below error.
Field 'deployment' does not exist in the data.

index=json
|rex mode=sed "s/.*-\s//g"
|spath
|rename ops{}.steps{}.steps{}.address{}.deployment as deployment 
|mvexpand deployment
|mvexpand operation
|table deployment

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Put the field name in double quotes (usually it is single quotes for field names but rename seems to operate differently)

|rename "ops{}.steps{}.steps{}.address{}.deployment" as deployment 
0 Karma

super_saiyan
Communicator

anyone ?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you don't have the deployment field, what fields do you have?

0 Karma

super_saiyan
Communicator

Hi, I have shared the logs with you in DM

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@super_saiyan 

Can you please share some sample events?

Meanwhile, you can try this rename as well. 

| rename "ops.steps.steps.address.deployment" as deployment

 

KV

0 Karma

super_saiyan
Communicator

Thanks much @kamlesh_vaghela 
I have shared the logs in DM, please check

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...