Splunk Search

When using "typeof, results are field value invalid

vsid_splunk
Explorer

I have used "typeof" to know the Types for fields for the data set in splunk web version, but I get the Value column showing invalid in each one of its corresponding rows.

Labels (1)
Tags (2)
0 Karma

top_splunker
New Member

@vsid_splunk  try putting single quotes around the field name that is returning as invalid.  

0 Karma

vsid_splunk
Explorer

@somesoni2 can you look at my search, sir?

0 Karma

vsid_splunk
Explorer

sourcetype = json | FieldsTypes

This macro definition of FieldsTypes is.... eval Ent_Code = typeof ('TableEntry.EventCode')

So @somesoni2 , im seeing the Ent_Code as invalid in "value" column after I click on "AllFields"

0 Karma

somesoni2
Revered Legend

Can you post your search?

0 Karma

vsid_splunk
Explorer

Can anyone "Please" Respond using #Tag. ASAP!

Raghav2384
Motivator

Never used typeof / didn't get there yet. May be this can help
http://answers.splunk.com/answers/177400/how-to-use-json-extracted-fields-with-eval-functio.html

cdstealer
Contributor

just ran into this myself. single quotes fixed it. Thanks

Get Updates on the Splunk Community!

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...

Announcing Our Splunk MVPs

We are excited to announce the first cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...