Splunk Search

When using "typeof, results are field value invalid

vsid_splunk
Explorer

I have used "typeof" to know the Types for fields for the data set in splunk web version, but I get the Value column showing invalid in each one of its corresponding rows.

Labels (1)
Tags (2)
0 Karma

top_splunker
Engager

@vsid_splunk  try putting single quotes around the field name that is returning as invalid.  

makelovenotwar
Path Finder

GENIUS!

0 Karma

vsid_splunk
Explorer

@somesoni2 can you look at my search, sir?

0 Karma

vsid_splunk
Explorer

sourcetype = json | FieldsTypes

This macro definition of FieldsTypes is.... eval Ent_Code = typeof ('TableEntry.EventCode')

So @somesoni2 , im seeing the Ent_Code as invalid in "value" column after I click on "AllFields"

0 Karma

somesoni2
Revered Legend

Can you post your search?

0 Karma

vsid_splunk
Explorer

Can anyone "Please" Respond using #Tag. ASAP!

Raghav2384
Motivator

Never used typeof / didn't get there yet. May be this can help
http://answers.splunk.com/answers/177400/how-to-use-json-extracted-fields-with-eval-functio.html

cdstealer
Contributor

just ran into this myself. single quotes fixed it. Thanks

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...