Hello,
I am trying to rename some fields pre-index using props.conf and it's not working. Props below.
[onelogin:event]
EVAL-app_name = app
EVAL-src_ip = ipaddr
Also tried using FIELDALIAS to no avail. The props file is local dir on the HF (/opt/splunk/etc/apps/splunk_ta_onelogin/local).
bt debug shows the intended config ..
/opt/splunk/etc/apps/splunk_ta_onelogin/local/props.conf [onelogin:event]
/opt/splunk/etc/apps/splunk_ta_onelogin/local/props.conf EVAL-app_name = app
/opt/splunk/etc/apps/splunk_ta_onelogin/local/props.conf EVAL-src_ip = ipaddr
Also tried putting the props file in system local, no effect. How do I troubleshoot this? Thanks!
Did you cycle Splunk after making changes?
Hi @oleg106
EVAL, FIELDALIAS are works during search-time hence they shall be deployed to SearchHead not HF.
---
An upvote would be appreciated and Accept solution if this reply helps!