Splunk Search

How can er rename the default field count ?

rakesh_498115
Motivator

Hi..

I am using the top command . Now i want to rename the count field that comes default with the top command . how can i do tat ??

I tried like this..

sourcetype="x" | top eventtype | rename count as ReqCount

But this is not workin..Please Help

Tags (1)
0 Karma
1 Solution

MHibbin
Influencer

How odd! ... similar searches work fine for me.

Do you receive the desired results? - only the column header does not change?

I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)

...Probably no help at all, just thought I would say/ask something..

🙂

View solution in original post

0 Karma

MHibbin
Influencer

How odd! ... similar searches work fine for me.

Do you receive the desired results? - only the column header does not change?

I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)

...Probably no help at all, just thought I would say/ask something..

🙂

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...