Knowledge Management

Field aliases not parsing fields from Exchange

kevinbriggs85
New Member

I am currently trying to parse data to map to a specific CIM-compliant field name. Specifically, I have setup a field alias as such:

AffectedItems{}.Attachments ASNEW file_name

After creating this alias, when I do a search for the data, I can see the original field in the data, but file_name is only a fraction of the total events (%s are based on results at the time of my most recent search):

  • AffectedItems{}.Attachments: 25.52% coverage
  • file_name: 0.08% coverage

To clarify, I am trying to normalize this data for the CIM Email Datamodel. The small coverage is from another sourcetype where I had created a field alias:

messageParts{}.filename ASNEW file_name

In this second sourcetype, it's a much smaller amount of data, but they have an identical coverage of 98.9%. At first we theorized it may be an issue with the curly braces, but one alias works, but not another. Looking to see if anyone has encountered a similar issue and knows the cause.

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...