alias

noun

A word you assign to an existing field name, so that you can search on events containing that field by using that word in the search. Any extracted field can have more than on alias, and a single alias can be applied to multiple fields. Creating an alias for a field does not rename or remove the original field name.

Unlike tags, aliases are not applied to specific field name/value combinations. They apply to every value of the aliased field.

Field aliasing can be used to normalize different field names to one name and simplify searching for those related fields. For source types, field aliasing is referred to as sourcetype renaming.

Related terms

For more information

In the Knowledge Manager Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time