Splunk Search

When using "typeof, results are field value invalid

vsid_splunk
Explorer

I have used "typeof" to know the Types for fields for the data set in splunk web version, but I get the Value column showing invalid in each one of its corresponding rows.

Labels (1)
Tags (2)
0 Karma

top_splunker
Engager

@vsid_splunk  try putting single quotes around the field name that is returning as invalid.  

makelovenotwar
Path Finder

GENIUS!

0 Karma

vsid_splunk
Explorer

@somesoni2 can you look at my search, sir?

0 Karma

vsid_splunk
Explorer

sourcetype = json | FieldsTypes

This macro definition of FieldsTypes is.... eval Ent_Code = typeof ('TableEntry.EventCode')

So @somesoni2 , im seeing the Ent_Code as invalid in "value" column after I click on "AllFields"

0 Karma

somesoni2
Revered Legend

Can you post your search?

0 Karma

vsid_splunk
Explorer

Can anyone "Please" Respond using #Tag. ASAP!

Raghav2384
Motivator

Never used typeof / didn't get there yet. May be this can help
http://answers.splunk.com/answers/177400/how-to-use-json-extracted-fields-with-eval-functio.html

cdstealer
Contributor

just ran into this myself. single quotes fixed it. Thanks

Get Updates on the Splunk Community!

Notification Email Migration Announcement

The Notification Team is migrating our email service provider from Postmark to AWS Simple Email Service (SES) ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...