Splunk Search

Field alias does not work in tstats?

phoenix_down
Path Finder

Hi all, I'm changing a field name in my index, so I'm trying to set up a field alias so both the old field name and new field name can be used in queries. This is for backward compatibility reasons, since a lot of existing dashboards/reports (many I do not own) refer to this field.

So I set up the field alias, and I find that the field alias works for a normal search (non-tstats), but does not work for tstats.  Does that mean field aliases do not work for tstats at all?

Labels (2)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I wouldn't be surprised. Remember that tstats work on indexed fields.
fields.conf don't allow for field aliases as far as I remember.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...