Hello, at the moment we are indexing JSON files in Splunk and then rename the fields with a Field Alias function. This leads to the problem, that we cannot use tStats on these renamed fields anymore.
Now to the question:
Hi @simon_b,
let me understand: you created some index-time fields from a json and you want to use aliases.
But the fields from a json aren't by default created ad index time, so, if you are creatingindex-time fields, you can create them using the names you like.
Anyway, are you sure that a search on index-time fields (with tstats) doesn't run with aliases?
I haven't index-time json extractions to test, but they shuld run with aliases.
Are you sure thta you extracted json fields at index-time?
Ciao.
Giuseppe