Knowledge Management

How to avoid duplicate fields in CIM Data Normalization?

Atchyuth_P
Path Finder

Hi Team,

I am using field aliases as in my sourcetype i have two common fields (dest & dest_ip) which have same values.
When i applied field aliases both were reflecting.

Atchyuth_P_0-1676313476036.png

Atchyuth_P_1-1676313720897.png

How to avoid duplicate fields

Kindly help in this scenario

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Having two aliases for the same field will result in 3 fields (the original plus 2 aliases) with the same data.  That may be necessary for some use cases, which means you have to live with it.  Fortunately, aliases are search-time operations so no storage is consumed.  If you don't have a need for multiple aliases for the same data then remove one of them.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...