Knowledge Management

How can I rename fields based on source?

snorri
Path Finder

I have data coming in from two different sources wich both contains the same fieldname.
how can I tell them apart in a search.

For example:
source1 have a field named ID and so does source2.
How can I rename the ID from source1 to ID1 and the ID from source2 to ID2?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI snorri,
if they are different sourcetype you can set an alias or a calculated field for one of the flows:
[Settings -- Fields -- Field Alias -- New ] setting the alias for that sourcetype.

If you have the same sourcetype you can use the same way using source instead sourcetype.

Bye.
Giuseppe

0 Karma

cmerriman
Super Champion

try this:

|eval ID1=if(source="source1",ID,null())
|eval ID2=if(source="source2",ID,null())

you could create an Event Type/Tag for these, so you don't have to keep distinguishing them in each search. Go to Settings>Event types

http://docs.splunk.com/Documentation/Splunk/7.0.0/Knowledge/Abouteventtypes

0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...