Splunk Search

How to typecast integer to string and save that to a new field?

DEAD_BEEF
Builder

I have a numeric field that needs to be string to put be CIM compliant. I tried using tostring, but it still shows up with the # in the interesting field list so it's still being read as a number. Also, how do I go about saving that field so it is always returned as a string to be used by the data model?

alt text

currently numeric field called

id
values      102342,23482,23498,23490

I want string field

id_string
values      102342,23482,23498,23490
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...