Creating Field Aliases and Calculated Fields Flashcards
What are field aliases?
Field aliases give you a way to normalize data over any default field (host, source, or sourcetype).
What options are you given for applying a field alias to?
- Sourcetype
- Source
- Host
True or False: Multiple aliases can be applied to a single field.
True, but it is not recommended.
True or False: Field Aliases are added to the fields sidebar.
True
True or False: When createing a field alias, the original field is affected.
False.
The original field is not affected.
Where do a field alias and the original field appear in the fields list?
Both fields appear in the All Fields and Interesting Fields lists, if they appear in at least 20% of the events.
In what order are the knowledge objects Field Aliases, Field Extractions, and Lookups applied?
Field Extractions, Field Aliases, Lookups
When are field aliases applied?
After field extractions, before lookups.
Are Field Aliases case sensitive?
Field aliases are also case sensitive as field names are case sensitive.
True or False: Field aliases can be referenced by a lookup file.
True.