Splunk Search

help on splunk field aliases not visible

jip31
Motivator

hello

 

I have a admin role

when I create a field alias, I can see it in the props.conf file but when I run the search the field names are unchanged

[sourcetype="Perfmon:mem"]
FIELDALIAS-Value = Value AS titi counter AS tutu

 

what is wrong please?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

when you use sourcetype, you don't need to specify it;

[Perfmon:mem]
FIELDALIAS-Value = Value AS titi counter AS tutu

only for host and source you have to specify them but with a different syntax:

[source::your_source]
FIELDALIAS-Value = Value AS titi counter AS tutu

[host::your_host]
FIELDALIAS-Value = Value AS titi counter AS tutu

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

when you use sourcetype, you don't need to specify it;

[Perfmon:mem]
FIELDALIAS-Value = Value AS titi counter AS tutu

only for host and source you have to specify them but with a different syntax:

[source::your_source]
FIELDALIAS-Value = Value AS titi counter AS tutu

[host::your_host]
FIELDALIAS-Value = Value AS titi counter AS tutu

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...