Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how to display a field two times in a table with the original values and after a rename of the values

$
0
0
hi As you can see below, I am doing a stats with the field "process_name" In order to be more comprenhensive, I am doing a rename of this field with a case function But in my table, I would like to display this field 2 times : one time with the original name and another time with the name done after the rename How I can do this please?? | stats values xxxxxx by host process_name | eval process_name=case(process_name like "mfev%" OR process_name like "mcdatrep" OR process_name=="mcshield") | rename process_name as "Process name" | table "Process name"

Viewing all articles
Browse latest Browse all 47296

Trending Articles