REPORT- is a search time extraction
FIELDALIAS- creates an alias for an existing field name, so if you already had a field such as ComputerName automatically extracted from windows event logs, you could create an alias to change it to comp_name for example.
Where have you seen FIELD- ? Its not documented.
Ah, best bet is to just post a comment asking if anyone had any ideas to bump it back up the list 🙂
REPORT- is a search time extraction
FIELDALIAS- creates an alias for an existing field name, so if you already had a field such as ComputerName automatically extracted from windows event logs, you could create an alias to change it to comp_name for example.
Where have you seen FIELD- ? Its not documented.
ah, I would assume it was a typo. If it did work it is probably just short-hand for FIELDALIAS much like Splunk doesn't care if you use TRANSFORM or TRANSFORMS
Thanks Drainy, I don't know exactly where I saw but I am sure it was either in Splunkbase or Answers.
Anyway Now after your reply there is no meaning of my question.
Thanks Drainy
Thanks Drainy,
my question is still open and unanswered. I didn't get any answer so thought better to close it because there is no delete option.
If you're happy its been answered then all you need to do is click the tick next to the answer below to accept it 🙂 If you've answered it elsewhere, post it as your own answer and then you can accept that too. We keep closing questions for spam or duplicates
Are you referring to REPORT-
http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf
Thanks for your reply.
I mean REPORT-