Splunk Search
Highlighted

Getting duplicate rename fields error after upgrade from 6.3.0 to 6.4.2

Motivator

The following search worked prior to upgrade:

| stats sparkline count dc(sourcetype) as sourcetype last(raw) as lastrawmsg values(sourcetype) as sourcetype last(time) as earliestmsgtime first(time) as latestmsgtime values(index) as index by punct
| eval delta=round((latest
msgtime-earliestmsgtime),0)
| eval msg
persec=round((count/delta),2)
| convert ctime(earliest
msgtime) ctime(latestmsgtime)
| table last
rawmsg count sourcetype sparkline msgpersec sourcetype earliestmsgtime latestmsg_time
| sort -count

Error in 'stats' command: 1 duplicate rename field(s)

0 Karma
Highlighted

Re: Getting duplicate rename fields error after upgrade from 6.3.0 to 6.4.2

SplunkTrust
SplunkTrust

You do have a duplicate stats functions dc(sourcetype) as sourcetype and values(sourcetype) as sourcetype. I can't imagine this would have worked in 6.3.0.

Any how, you can (should) change the name of one of them.

View solution in original post

Highlighted

Re: Getting duplicate rename fields error after upgrade from 6.3.0 to 6.4.2

Motivator

Thanks, Somesh
My brain wasn't registering that "as" is equivalent to the "rename" command.

Rob

0 Karma