Getting Data In

kvmode=json and field aliases

rdownie
Communicator

When using kvmode=json to carve fields, when I try to create a field alias to make the fields CIM compliant, they don't appear to take. I assume there is a precedence here. Is there a way to accomplish this while still having the fields initially extracted with kvmode?
Any help would be appreciated.
Thanks,
-Bob

woodcock
Esteemed Legend

Are you saying, "I have complete control of the format of my logs which are in json format and I am adding field names that are CIM-compliant"? If so, then the only thing that could be wrong is that you're event is not fully-valid json but in that case it would not be some fields that are missing; it would be ALL fields.

0 Karma

pruthvikrishnap
Contributor

Hi RD,

I did face a similar issue before, i did force some required fields, which worked in my case.
https://answers.splunk.com/answers/562805/how-to-force-to-set-certain-fields-host-and-source.html

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...