Knowledge Management

Is it possible to create a field alias on a lookup output field for mapping to the CIM model?

jmteo
Explorer

Hi guys,

I am in the midst of trying to map the fields in my data to the splunk authentication CIM. However, I realised that I don't seem able to create a field alias on lookup output fields (eg. Interfaces [lookup output field] => App [CIM field]) {ie This field aliases don't show up}. Is it possible to create a field alias for mapping my lookup output field to the CIM model, and if there isn't, could I kindly request for your suggestion as to what I can do to map my lookup fields to the CIM Model? Thanks and have a pleasant day/evening ahead 🙂

0 Karma
1 Solution

FrankVl
Ultra Champion

You can do that straight in the lookup action, by writing the output side of the lookup as OUTPUT <output_field> AS <output_field_in_event>

View solution in original post

0 Karma

FrankVl
Ultra Champion

You can do that straight in the lookup action, by writing the output side of the lookup as OUTPUT <output_field> AS <output_field_in_event>

0 Karma

jmteo
Explorer

Guess I overlooked that. Thanks 🙂

0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...