Splunk Search

When using "typeof, results are field value invalid

vsid_splunk
Explorer

I have used "typeof" to know the Types for fields for the data set in splunk web version, but I get the Value column showing invalid in each one of its corresponding rows.

Labels (1)
Tags (2)
0 Karma

top_splunker
New Member

@vsid_splunk  try putting single quotes around the field name that is returning as invalid.  

0 Karma

vsid_splunk
Explorer

@somesoni2 can you look at my search, sir?

0 Karma

vsid_splunk
Explorer

sourcetype = json | FieldsTypes

This macro definition of FieldsTypes is.... eval Ent_Code = typeof ('TableEntry.EventCode')

So @somesoni2 , im seeing the Ent_Code as invalid in "value" column after I click on "AllFields"

0 Karma

somesoni2
Revered Legend

Can you post your search?

0 Karma

vsid_splunk
Explorer

Can anyone "Please" Respond using #Tag. ASAP!

Raghav2384
Motivator

Never used typeof / didn't get there yet. May be this can help
http://answers.splunk.com/answers/177400/how-to-use-json-extracted-fields-with-eval-functio.html

cdstealer
Contributor

just ran into this myself. single quotes fixed it. Thanks

Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...