For the search app, I want to modify a field called "partner" (new field added when data is sent to Splunk in receivers endpoint) with a value of "Yan Yi" and replace the "partner" field value to
"muktar".
I put in this search command in the search app,
sourcetype = " sexuality" | replace Yan Yi with muktar in partner
The search app threw an error :
[EventsViewer module] Error in 'replace' command : Usage replace[orig_str WITH new_str] + [IN field1,field2,..]
What is the issue with this? Is there any way i could correact the syntax of the search command??
You need to enclose "Yan Yi" in quotes.