Splunk Search

rename the name of a field with the value of another field

marziaolla
Path Finder

Hello there,

After a stats command, I would like to rename the name of a field using a string and the value of another field
eg. fieldname i'd like -> "ABC 2018" but 2018 is stored in a field

I've tried with eval {ABC}="ABC".year but it doesn't work.

can someone help me?
TNX 🙂

0 Karma

woodcock
Esteemed Legend

Like this:

| makeresults
| eval XYZ="123"
| eval year="2018"
| rename StuffBelowIsTheSame AS "rename XYZ AS ABC2018"
| eval newname="ABC" . year
| eval {newname}=XYZ
| fields - newname XYZ

renjith_nair
Legend

@marziaolla,

Try this

| makeresults |eval abc="123",xyz="567"|eval tmp="abc".xyz|eval {tmp}="To be replaced by value of field"|fields - tmp
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

renjith_nair
Legend

@marziaolla, did it work for you ?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...