when i run below search its extracting data from AWS bucket so how ican convert this to search time in splunk cloud add to permanently.
index=test "aws.guardduty" | rename "BodyJson.detail."* as "detail."* | rename "BodyJson."* as ""*
There is no such thing as an automatic rename
in Splunk. The closes that you can get are automatic field aliases
but these do not support wildcards so you will have to iterate the entire namespaces.
hmm care to elaborate with an example, if possible?