Hi,
I am using multiple sources in a single search command and i want to rename the _raw field of one of the source type.
My current search:
sourcetype="blacklisted ip" OR sourcetype="log" | rename _raw as blacklisted
I want to change the _raw field of blacklisted ip into blacklisted, and leave the _raw field of log as default.
Thanks a lot.
sourcetype="a" OR sourcetype="b" | eval blacklisted=if(sourcetype=="a",_raw,null())
sourcetype="a" OR sourcetype="b" | eval blacklisted=if(sourcetype=="a",_raw,null())
If you want to get rid of the data of the specific sourcetype please use the transforms.conf file to null queue... And yes you can rename the _raw field as well, but its temporary.