Splunk Search

How can er rename the default field count ?

rakesh_498115
Motivator

Hi..

I am using the top command . Now i want to rename the count field that comes default with the top command . how can i do tat ??

I tried like this..

sourcetype="x" | top eventtype | rename count as ReqCount

But this is not workin..Please Help

Tags (1)
0 Karma
1 Solution

MHibbin
Influencer

How odd! ... similar searches work fine for me.

Do you receive the desired results? - only the column header does not change?

I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)

...Probably no help at all, just thought I would say/ask something..

🙂

View solution in original post

0 Karma

MHibbin
Influencer

How odd! ... similar searches work fine for me.

Do you receive the desired results? - only the column header does not change?

I think it makes no difference what-so-ever with "rename"... but you could tried putting "as" in caps, like "AS", somethings are case-sensitive in Splunk (but I don't use "AS", so don't know)

...Probably no help at all, just thought I would say/ask something..

🙂

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...