<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic using a inputlookup on string values - regex match? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54528#M13306</link>
    <description>&lt;P&gt;I am currently matching a list of "bad ips" with a search such as this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=someindex NOT uri="/dot_clear.gif" [| inputlookup watchlist_ip_lookup.csv  | rename watch_ip as clientip | fields + clientip] | dedup clientip | lookup ga ip as clientip | table date_month, date_mday, date_hour, date_minute, date_year, clientip, country, org, status, referer, uri, host, source, sourcetype, index, other
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;how can i do a similar search with a partial text match in say the URI, say from sourcetype access_combined searching on a partial domain match like &lt;CODE&gt;.*somedomain.com.*&lt;/CODE&gt; ?&lt;BR /&gt;
I would like to use these domain strings in a inputlookup table like the ip list i attached above&lt;BR /&gt;
possibly with a rex match on the uri? i am just not getting the format right.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Sep 2012 17:18:35 GMT</pubDate>
    <dc:creator>sonicZ</dc:creator>
    <dc:date>2012-09-07T17:18:35Z</dc:date>
    <item>
      <title>using a inputlookup on string values - regex match?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54528#M13306</link>
      <description>&lt;P&gt;I am currently matching a list of "bad ips" with a search such as this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=someindex NOT uri="/dot_clear.gif" [| inputlookup watchlist_ip_lookup.csv  | rename watch_ip as clientip | fields + clientip] | dedup clientip | lookup ga ip as clientip | table date_month, date_mday, date_hour, date_minute, date_year, clientip, country, org, status, referer, uri, host, source, sourcetype, index, other
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;how can i do a similar search with a partial text match in say the URI, say from sourcetype access_combined searching on a partial domain match like &lt;CODE&gt;.*somedomain.com.*&lt;/CODE&gt; ?&lt;BR /&gt;
I would like to use these domain strings in a inputlookup table like the ip list i attached above&lt;BR /&gt;
possibly with a rex match on the uri? i am just not getting the format right.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2012 17:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54528#M13306</guid>
      <dc:creator>sonicZ</dc:creator>
      <dc:date>2012-09-07T17:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: using a inputlookup on string values - regex match?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54529#M13307</link>
      <description>&lt;P&gt;If it's just a matter of using wildcards, you can let the regular search command take care of that.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=someindex NOT [|inputlookup yourlookup | eval query="uri=*".domain."*" | fields query] | ...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 07 Sep 2012 21:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54529#M13307</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-07T21:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: using a inputlookup on string values - regex match?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54530#M13308</link>
      <description>&lt;P&gt;Thanks Ayn, i changed domain to my "watch_list" header in the csv and that works for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
Edit: &lt;BR /&gt;
actually i removed the NOT too, this and it seems to work&lt;/P&gt;

&lt;P&gt;index=someindex NOT uri="/dot_clear.gif"  earliest=-1h [|inputlookup watchlist_string_lookup | eval query="uri=&lt;EM&gt;".watch_string."&lt;/EM&gt;" | fields query] | lookup ga ip as clientip | table date_month, date_mday, date_hour, date_minute, date_year, clientip, country, org, status, referer, uri, host, source, sourcetype, index, other&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:24:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54530#M13308</guid>
      <dc:creator>sonicZ</dc:creator>
      <dc:date>2020-09-28T12:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: using a inputlookup on string values - regex match?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54531#M13309</link>
      <description>&lt;P&gt;Ayn, another follow up question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
If i wanted to match on a string anywhere in the _raw events, But seems rather slow on large indexes.&lt;BR /&gt;
Perhaps there is a better way.&lt;/P&gt;

&lt;P&gt;index=www NOT uri="/dot_clear.gif" [|inputlookup watchlist_string_lookup | eval query="_raw=&lt;EM&gt;".watch_string."&lt;/EM&gt;" | fields query] | lookup ga ip as clientip | table date_month, date_mday, date_hour, date_minute, date_year, clientip, country, org, status, referer, uri, host, source, sourcetype, index, other, watch_string&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-a-inputlookup-on-string-values-regex-match/m-p/54531#M13309</guid>
      <dc:creator>sonicZ</dc:creator>
      <dc:date>2020-09-28T12:29:17Z</dc:date>
    </item>
  </channel>
</rss>

