Hello 🙂
I have splunk getting data from a folder everyday.
Recently the files changed the name of the fields.
Here is a sample there are 44 fields in total,
Old New
Number number
Correlation ID correlation_id
Opened opened_at
Priority priority
Category category
Site u_customer_site
Domain u_domain
Nature u_nature
I was wondering if there is anyway i can make this change without needing to add to every single dashboard the | rename as 44 times.
Add 44 FIELDALIAS settings in the appropriate props.conf stanza.
Add 44 FIELDALIAS settings in the appropriate props.conf stanza.
You could put the renames in a macro and then call the macro from your dashboards.