Getting Data In

Sourctype and fix jason field data

Splunk_rocks
Path Finder

when i run below search its extracting data from AWS bucket so how ican convert this to search time in splunk cloud add to permanently.

index=test "aws.guardduty"  | rename "BodyJson.detail."* as "detail."*  | rename "BodyJson."* as ""* 
Tags (1)
0 Karma

woodcock
Esteemed Legend

There is no such thing as an automatic rename in Splunk. The closes that you can get are automatic field aliases but these do not support wildcards so you will have to iterate the entire namespaces.

0 Karma

Sukisen1981
Champion

hmm care to elaborate with an example, if possible?

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...