Hi
I need to rename a field name (from lookup csv) with special character inside, like:
Service*
Status+
the problem is the: *
inputlookup file.csv | rename "Service*" as service
... does not work. how can i tell splunk to ignore the * as "wildcard"?
thanks
| stats count
| rename count as "Status*"
| eval status='Status*'
| fields status
Hi, this is sample query.
| inputlookup file.csv
| eval service='Service*'
| fields - Service*
How about this?
Can you please try the below.
inputlookup file.csv | rename 'Service*' as service
Instead of using '' please use '
thank you
| rename 'Service*' as service
does not work.
the solution at the end (thanks to to4kawa) is:
|inputlookup report.csv
| rename count as "Status*"
| eval status='Status*'
| stats count
| rename count as "Status*"
| eval status='Status*'
| fields status
Hi, this is sample query.
| inputlookup file.csv
| eval service='Service*'
| fields - Service*
How about this?
thank you so much to4kawa!
this helps:
|inputlookup report.csv
| rename count as "Status*"
| eval status='Status*'
have a good day and thanks
Hi
at the end, this works fine:
|inputlookup report.csv
| rename count as "Status*"
| eval status='Status*'
thank you so much
your welcome, Happy Splunking.
If you just need to change the column name, look at installing the Lookup Editor https://splunkbase.splunk.com/app/1724/. If the lookup is larger than 10 mb and you don't need the field names, I would just re-upload the lookup with the fields you want.
thank you - i can just upload the report as "user" - in settings/lookups - therefore not able to rename column during import (like when splunk is locally installed).