Splunk Search

Translate Column values

michael_lee
Path Finder

Hi,
Say I have indexed a file that has this structure:

1|A|B
2|C|D

I have a mapping like this :

1="Val1"
2="Val2"

Only the first column need to be translated. Hence when user search for "B", I want to return

Val1|A|B

How can this done?
Thanks

Tags (3)
0 Karma
1 Solution

vganjare
Builder

vganjare
Builder

HI,

This can be done using Field aliasing. More details @ http://docs.splunk.com/Documentation/Splunk/6.2.3/Knowledge/Addaliasestofields

Thanks!!

Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...