Getting Data In

kvmode=json and field aliases

rdownie
Communicator

When using kvmode=json to carve fields, when I try to create a field alias to make the fields CIM compliant, they don't appear to take. I assume there is a precedence here. Is there a way to accomplish this while still having the fields initially extracted with kvmode?
Any help would be appreciated.
Thanks,
-Bob

woodcock
Esteemed Legend

Are you saying, "I have complete control of the format of my logs which are in json format and I am adding field names that are CIM-compliant"? If so, then the only thing that could be wrong is that you're event is not fully-valid json but in that case it would not be some fields that are missing; it would be ALL fields.

0 Karma

pruthvikrishnap
Contributor

Hi RD,

I did face a similar issue before, i did force some required fields, which worked in my case.
https://answers.splunk.com/answers/562805/how-to-force-to-set-certain-fields-host-and-source.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...