Splunk Search

Rename column name in stats

jayavasge
New Member

index =* "log" earliest =@d-4h latest=@d+8h | rex "(?\w*)<" | dedup ticketId | stats count as today

Want to rename column name(today) into event date. Kindly support.

Tags (1)
0 Karma

renjith_nair
Legend

@jayavasge ,

index = "log" earliest =@d-4h latest=@d+8h | rex "(?\w)<" | dedup ticketId | stats count as "event date"
---
What goes around comes around. If it helps, hit it with Karma 🙂

chrisyounger
SplunkTrust
SplunkTrust

Give this a burl: index = "log" earliest =@d-4h latest=@d+8h | rex "(?\w)<" | dedup ticketId | stats count as today| rename today as "event date"

Good luck!

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...