All,
I have a lookup, which I in turn want to do a couple aliases on. But doesn't seem to work. I get clienthost back, but the aliases don't. Any idea what I might be doing wrong here?
## Some DNS
FIELDALIAS-real_ip_as_clientip = real_ip as clientip
LOOKUP-dns = dnslookup clientip OUTPUT clienthost
FIELDALIAS-clienthost_as_src_host = clienthost AS src_host
FIELDALIAS-clienthost_as_src_dns = clienthost AS src_dns
Have a look at this really nice Splunk documentation which provides sequence of all search time operation.
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Searchtimeoperationssequence
The Field Aliasing happes before Lookup, that's the reason you don't see your clienthost aliases.
Have a look at this really nice Splunk documentation which provides sequence of all search time operation.
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Searchtimeoperationssequence
The Field Aliasing happes before Lookup, that's the reason you don't see your clienthost aliases.
Dang, that's no good. Any work around for this?
This might work:
LOOKUP-dns = dnslookup clientip OUTPUT clienthost clienthost as src_host clienthost as src_dns
basically lookup is outputting 3 fields (same field with different names)