Skip to content

Commit

Permalink
Merge pull request #622 from CrossRealms/fields-with-dot-is-not-displ…
Browse files Browse the repository at this point in the history
…aying-properly

fixed the display issue for the fields having dot in it
  • Loading branch information
hardikhdholariya authored Sep 3, 2024
2 parents 829eda0 + 6505188 commit 349e9fa
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -499,7 +499,7 @@ require([

this._searchManagerNotableEventResult.executeReusableSearch(`\`cs_cyences_index\` notable_event_id="${notable_event_id}" | fields - _raw, notable_event_id, search_name, alert_name, category, info_min_time, info_max_time, info_search_time, search_now, timestartpos, timeendpos, eventtype, linecount, splunk_server, splunk_server_group, tag, "tag::*", date_*, host, index, source, sourcetype, avoid_es_fields
| rename * AS X_*_NEW
| foreach * [ eval newFieldName=replace("<<FIELD>>", "\\s+", "_"), {newFieldName}='<<FIELD>>' ] | fields - "* *", newFieldName
| foreach * [ eval newFieldName=replace("<<FIELD>>", "\\s+|\\.+", "_"), {newFieldName}='<<FIELD>>' ] | fields - "* *", newFieldName
| foreach X_*_NEW [ eval <<MATCHSTR>>=<<FIELD>> ]
| fields - X_*_NEW
| rename orig_* as *
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
| search cyences_severity IN $tkn_severity$
| fields - _raw, search_name, alert_name, category, info_min_time, info_max_time, info_search_time, search_now, timestartpos, timeendpos, eventtype, linecount, splunk_server, splunk_server_group, tag, "tag::*", date_*, host, index, source, sourcetype, avoid_es_fields
| rename * AS X_*_NEW
| foreach * [ eval newFieldName=replace("&lt;&lt;FIELD&gt;&gt;", "\s+", "_"), {newFieldName}='&lt;&lt;FIELD&gt;&gt;' ] | fields - "* *", newFieldName
| foreach * [ eval newFieldName=replace("&lt;&lt;FIELD&gt;&gt;", "\s+|\.+", "_"), {newFieldName}='&lt;&lt;FIELD&gt;&gt;' ] | fields - "* *", newFieldName
| foreach X_*_NEW [ eval &lt;&lt;MATCHSTR&gt;&gt;=&lt;&lt;FIELD&gt;&gt; ]
| fields - X_*_NEW
| rename orig_* as *
Expand Down
2 changes: 1 addition & 1 deletion cyences_app_for_splunk/default/data/ui/views/cs_soc.xml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
| search cyences_severity IN $tkn_severity$
| fields - _raw, search_name, category, info_min_time, info_max_time, info_search_time, search_now, timestartpos, timeendpos, eventtype, linecount, splunk_server, splunk_server_group, tag, "tag::*", date_*, host, index, source, sourcetype, avoid_es_fields
| rename * AS X_*_NEW
| foreach * [ eval newFieldName=replace("&lt;&lt;FIELD&gt;&gt;", "\s+", "_"), {newFieldName}='&lt;&lt;FIELD&gt;&gt;' ] | fields - "* *", newFieldName
| foreach * [ eval newFieldName=replace("&lt;&lt;FIELD&gt;&gt;", "\s+|\.+", "_"), {newFieldName}='&lt;&lt;FIELD&gt;&gt;' ] | fields - "* *", newFieldName
| foreach X_*_NEW [ eval &lt;&lt;MATCHSTR&gt;&gt;=&lt;&lt;FIELD&gt;&gt; ]
| fields - X_*_NEW
| rename orig_* as *
Expand Down

0 comments on commit 349e9fa

Please sign in to comment.