New to Splunk. Trying to use the "as" command modifier to change the name of a column. However, the modifier is not being highlighted or changing the column name.
Here is my SPL string:
sourcetype="access_combined_wcookie" status=200 file="success.do"
| table JSESSIONID as UserSession
Hi Grook,
U will have to rename the command prior to |table, such as
| rename JSESSIONID as usersession
and then call it to table
Like this?
sourcetype="access_combined_wcookie" status=200 file="success.do"
| rename JSESSIONID as UserSessions
| table UserSession
Seems typo, field name should match, so if you rename you should use exact field name afterwards.
| rename JSESSIONID as UserSessions
| table UserSessions
If you have space or special characters in the field name you should use double quotes. For example
| rename JSESSIONID as "User Session IDs"
| table "User Session IDs"
yeah did it work?