Knowledge Management

Why a cloned field alias does not work as the original despite having identical permissions and app context?

att35
Builder

Hi,

Trying to map fields from eStreamer data to the ones needed by IDS data model. One of the fields which comes from Sourcefire is "priority" for which there is an existing field alias ( priority -> severity_id), which works fine.

Since CIM needs the field name to be 'severity', I cloned another field alias ( priority -> severity) from the existing and made sure that it has global permission and is part of the TA for sourcefire, same as the field alias for "severity_id".

Still, only severity_id is working but not the one newly created for "severity". Also tried creating the same on indexer but it didn't work. Here is a screenshot showing both the aliases.

alt text

Please advise.

Thanks,

0 Karma

neelamsantosh
Path Finder

check the props and make sure Field alias is happening only after the Fields extraction

cmd:
/opt/splunk/bin/splunk cmd btool props list --debug|grep

0 Karma

dsrvern
Explorer

Hi abhijittikekar,

I'm also experiencing problems with field aliases. Did you ever find a solution to this issue?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...