Splunk Search

Spath and Rename

IRHM73
Motivator

Hi, I wonder whether someone may be able to help me please.

I'm trying to create a query which extracts given values using 'spath'.

This is what I've come up with so far:

| multisearch
[ search `cc-frontend_wmf(cCurrentYearIncome)`]
[ search `cc-frontend_wmf(pCurrentYearIncome)`]
| spath output=claimant path=detail.cCurrentYearIncome
| spath output=partner path=detail.pCurrentYearIncome

I can create the "claimant" and "partner" fields, but I then need to perform a rename and this is where I have the problem because the fields I need to rename have the same name as shown below.

field=claim need to rename currentIncome.employmentIncome as ccurrent
field=part need to rename currentIncome.employmentIncome as pcurrent

Could someone tell me please is there a way to differentiate the two fields ie. is there a way to rename when I create the spath?

Many thanks and kind regards

Chris

0 Karma
1 Solution

IRHM73
Motivator

Hi,

I've fixed the issue by using the following:

| spath output=current input=detail.cCurrentYearIncome path=currentIncome.employmentIncome
| spath output=pcurrent input=detail.pCurrentYearIncome path=currentIncome.employmentIncome

Many thanks

Chris

View solution in original post

IRHM73
Motivator

Hi,

I've fixed the issue by using the following:

| spath output=current input=detail.cCurrentYearIncome path=currentIncome.employmentIncome
| spath output=pcurrent input=detail.pCurrentYearIncome path=currentIncome.employmentIncome

Many thanks

Chris

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...