Splunk Search

How can I display an apostrophe in a column title?

usernamejpblais
Engager

I'm trying to put an apostrophe in a colunm title into a dashboard I tried with renameand fieldformat but it does'nt work.

| rename trCount as "Nombre d'appel"

or

| fieldformat "Nombre d'appel" = tostring('Nombre appel',"Commas")

In fieldformat when I do as above I get a colunm with the right title but I got 2 colunm: Nombre d'appel AND Nombre appel.
I only want Nombre d'appel.

Thx a lot!!!

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@usernamejpblais

I think rename will work for you. See this:

| makeresults | eval trCount ="ABCD" | rename trCount as "Nombre d'appel"

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...