Getting Data In

kvmode=json and field aliases

rdownie
Communicator

When using kvmode=json to carve fields, when I try to create a field alias to make the fields CIM compliant, they don't appear to take. I assume there is a precedence here. Is there a way to accomplish this while still having the fields initially extracted with kvmode?
Any help would be appreciated.
Thanks,
-Bob

woodcock
Esteemed Legend

Are you saying, "I have complete control of the format of my logs which are in json format and I am adding field names that are CIM-compliant"? If so, then the only thing that could be wrong is that you're event is not fully-valid json but in that case it would not be some fields that are missing; it would be ALL fields.

0 Karma

pruthvikrishnap
Contributor

Hi RD,

I did face a similar issue before, i did force some required fields, which worked in my case.
https://answers.splunk.com/answers/562805/how-to-force-to-set-certain-fields-host-and-source.html

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...