Splunk Search

Alias bug that merge "NEW" word into new field

sonsee78
New Member

Hello,
I have been watching a problem when I was using alias function through the SPLUNK Web.
That problem was merged "NEW" word, both have Web and CLI.

WEB UI
Field aliases
Fields » Field aliases

Name    Field aliases   Owner   App Sharing Status  Actions
syslog : FIELDALIAS-process_to_pcs  process ASNEW pcs  admin  search Global | Permissions   Enabled Clone | Move | Delete

CLI

/opt/splunk/etc/system/local/props.conf
[syslog]
FIELDALIAS-process_to_pcs = process ASNEW pcs

Best Regards

0 Karma

sonsee78
New Member

I saw bug at the SPLUNK Enterprise version 7.3.0.

0 Karma

niketn
Legend

@sonsee78 use the option Overwrite field values while creating Field Alias otherwise above is expected behavior.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...