Splunk Search

field alias limit?

jagresz
Explorer

Hi,

Are there any limitations in amount of alias fields or is it a bug in 4.3.2 that fields are randomly aliased?

I want to collect return codes extracted from several sources with field aliases, and if I search:

search * | top ret-code1 (ret-code1 is the field extraction regex for source1, it gives 1000s hits)

search * | top common-ret-code (common-ret-code is the fieldalias name, it gives just couple of hits)

I digged in archive but not found relevant answer.

Thanks in advance:

JI

Tags (1)

jagresz
Explorer

Note: if I create a new fieldalias it works perfect! (common-ret-code contains several field aliases, this new contains only one) Still, I want to use common-ret-code, create a new one is not an option for me!
Thanks!
JI

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...