Splunk Search

When using "typeof, results are field value invalid

vsid_splunk
Explorer

I have used "typeof" to know the Types for fields for the data set in splunk web version, but I get the Value column showing invalid in each one of its corresponding rows.

Labels (1)
Tags (2)
0 Karma

top_splunker
Engager

@vsid_splunk  try putting single quotes around the field name that is returning as invalid.  

makelovenotwar
Path Finder

GENIUS!

0 Karma

vsid_splunk
Explorer

@somesoni2 can you look at my search, sir?

0 Karma

vsid_splunk
Explorer

sourcetype = json | FieldsTypes

This macro definition of FieldsTypes is.... eval Ent_Code = typeof ('TableEntry.EventCode')

So @somesoni2 , im seeing the Ent_Code as invalid in "value" column after I click on "AllFields"

0 Karma

somesoni2
Revered Legend

Can you post your search?

0 Karma

vsid_splunk
Explorer

Can anyone "Please" Respond using #Tag. ASAP!

Raghav2384
Motivator

Never used typeof / didn't get there yet. May be this can help
http://answers.splunk.com/answers/177400/how-to-use-json-extracted-fields-with-eval-functio.html

cdstealer
Contributor

just ran into this myself. single quotes fixed it. Thanks

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...