Knowledge Management

How to avoid duplicate fields in CIM Data Normalization?

Atchyuth_P
Path Finder

Hi Team,

I am using field aliases as in my sourcetype i have two common fields (dest & dest_ip) which have same values.
When i applied field aliases both were reflecting.

Atchyuth_P_0-1676313476036.png

Atchyuth_P_1-1676313720897.png

How to avoid duplicate fields

Kindly help in this scenario

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Having two aliases for the same field will result in 3 fields (the original plus 2 aliases) with the same data.  That may be necessary for some use cases, which means you have to live with it.  Fortunately, aliases are search-time operations so no storage is consumed.  If you don't have a need for multiple aliases for the same data then remove one of them.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...