Knowledge Management

Is it possible to create a field alias on a lookup output field for mapping to the CIM model?

jmteo
Explorer

Hi guys,

I am in the midst of trying to map the fields in my data to the splunk authentication CIM. However, I realised that I don't seem able to create a field alias on lookup output fields (eg. Interfaces [lookup output field] => App [CIM field]) {ie This field aliases don't show up}. Is it possible to create a field alias for mapping my lookup output field to the CIM model, and if there isn't, could I kindly request for your suggestion as to what I can do to map my lookup fields to the CIM Model? Thanks and have a pleasant day/evening ahead 🙂

0 Karma
1 Solution

FrankVl
Ultra Champion

You can do that straight in the lookup action, by writing the output side of the lookup as OUTPUT <output_field> AS <output_field_in_event>

View solution in original post

0 Karma

FrankVl
Ultra Champion

You can do that straight in the lookup action, by writing the output side of the lookup as OUTPUT <output_field> AS <output_field_in_event>

0 Karma

jmteo
Explorer

Guess I overlooked that. Thanks 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...