Splunk Search

Alias not working when running a search


Hi there,

I have multiple fields being extracted and aliased. These all work fine if i search by index & sourcetype. As soon as I try to use stats or table them all, the rows come up empty for the fields using the alias. Any thoughts on why this happens?


0 Karma

Path Finder

share some sample search commands to review what's wrong.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.