What you’re asking for is essentially schema validation at query compile time, which Splunk doesn’t currently support in SPL. This is a known gap, especially for teams used to SQL-like systems. The official route is to submit or upvote an idea on Splunk Ideas. Feature requests like this do occasionally get traction, especially around developer experience.
... View more