Splunk Search

Spath and Rename

IRHM73
Motivator

Hi, I wonder whether someone may be able to help me please.

I'm trying to create a query which extracts given values using 'spath'.

This is what I've come up with so far:

| multisearch
[ search `cc-frontend_wmf(cCurrentYearIncome)`]
[ search `cc-frontend_wmf(pCurrentYearIncome)`]
| spath output=claimant path=detail.cCurrentYearIncome
| spath output=partner path=detail.pCurrentYearIncome

I can create the "claimant" and "partner" fields, but I then need to perform a rename and this is where I have the problem because the fields I need to rename have the same name as shown below.

field=claim need to rename currentIncome.employmentIncome as ccurrent
field=part need to rename currentIncome.employmentIncome as pcurrent

Could someone tell me please is there a way to differentiate the two fields ie. is there a way to rename when I create the spath?

Many thanks and kind regards

Chris

0 Karma
1 Solution

IRHM73
Motivator

Hi,

I've fixed the issue by using the following:

| spath output=current input=detail.cCurrentYearIncome path=currentIncome.employmentIncome
| spath output=pcurrent input=detail.pCurrentYearIncome path=currentIncome.employmentIncome

Many thanks

Chris

View solution in original post

IRHM73
Motivator

Hi,

I've fixed the issue by using the following:

| spath output=current input=detail.cCurrentYearIncome path=currentIncome.employmentIncome
| spath output=pcurrent input=detail.pCurrentYearIncome path=currentIncome.employmentIncome

Many thanks

Chris

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...