Splunk Search

Alias not working when running a search

Builder

Hi there,

I have multiple fields being extracted and aliased. These all work fine if i search by index & sourcetype. As soon as I try to use stats or table them all, the rows come up empty for the fields using the alias. Any thoughts on why this happens?

Thanks!

0 Karma

Path Finder

share some sample search commands to review what's wrong.

0 Karma