<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How To Use Eval to Capture Inconsistent key:values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742747#M240937</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171511"&gt;@mark_groenveld&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the full event or a field in your event? Is the whole event JSON? If possible please give some full examples.&lt;/P&gt;&lt;P&gt;Are the names of the 3 cluster always CLUSTER followed by a single character?&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 22:11:54 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-03-26T22:11:54Z</dc:date>
    <item>
      <title>How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742740#M240932</link>
      <description>&lt;P&gt;I am searching for a key:value report app where the values are inconsistent but include a report cluster name consistently.&lt;/P&gt;&lt;P&gt;Example of key:value&lt;BR /&gt;APP_Details:{"CLUSTER_VIP":"CLUSTERX.URL.COM","Access":true}&lt;/P&gt;&lt;P&gt;There are over 100 APP_Details values for CLUSTERX.&lt;/P&gt;&lt;P&gt;How can I extract CLUSTERX (there are three different cluster names) to show as a single value by cluster?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 18:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742740#M240932</guid>
      <dc:creator>mark_groenveld</dc:creator>
      <dc:date>2025-03-26T18:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742741#M240933</link>
      <description>&lt;P&gt;I'm not sure what you mean by "extract" in this context. Do you have your fields extracted already and used it in a different meaning or do you want to extract values from the raw data? Give us a bit more example events and describe what would be the result (based on that example data) and why.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 18:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742741#M240933</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-26T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742742#M240934</link>
      <description>&lt;P&gt;Sure.&lt;/P&gt;&lt;P&gt;Here are examples of the values.&lt;/P&gt;&lt;P&gt;{"CLUSTER1.COM","viewSiteAsUser.hasAccess":true}&lt;/P&gt;&lt;P&gt;{"CLUSTER_VIP":"CLUSTER1.COM"}&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 19:04:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742742#M240934</guid>
      <dc:creator>mark_groenveld</dc:creator>
      <dc:date>2025-03-26T19:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742747#M240937</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171511"&gt;@mark_groenveld&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the full event or a field in your event? Is the whole event JSON? If possible please give some full examples.&lt;/P&gt;&lt;P&gt;Are the names of the 3 cluster always CLUSTER followed by a single character?&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 22:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742747#M240937</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-26T22:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742866#M240967</link>
      <description>&lt;P&gt;Here are 2 examples of the values for the events:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"CLUSTER1.COM","viewSiteAsUser.hasAccess":true}&lt;/P&gt;&lt;P&gt;{"CLUSTER_VIP":"CLUSTER1.COM"}&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 18:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742866#M240967</guid>
      <dc:creator>mark_groenveld</dc:creator>
      <dc:date>2025-03-27T18:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742868#M240968</link>
      <description>&lt;P&gt;I am looking for a way to pull out CLUSTER1 as a single value as there are two other clusters, CLUSTER2 AND CLUSTER3.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 18:37:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742868#M240968</guid>
      <dc:creator>mark_groenveld</dc:creator>
      <dc:date>2025-03-27T18:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742876#M240974</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171511"&gt;@mark_groenveld&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the samples dont look to be valid JSON, I assume we can use the *rex* command on them against the _raw field.&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "(?&amp;lt;ClusterVal&amp;gt;CLUSTER[0-9]+)"&lt;/LI-CODE&gt;&lt;P&gt;This should give you a field called ClusterVal with your cluster in it.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 21:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742876#M240974</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-27T21:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742968#M240987</link>
      <description>&lt;P&gt;Thanks for posting livehybrid. &amp;nbsp;The rex did not work. &amp;nbsp;Karma points to you for giving it a go&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":oncoming_fist:"&gt;👊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 18:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742968#M240987</guid>
      <dc:creator>mark_groenveld</dc:creator>
      <dc:date>2025-03-28T18:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: How To Use Eval to Capture Inconsistent key:values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742978#M240990</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171511"&gt;@mark_groenveld&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rex does work with the "events" you shared (as demonstrated below)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| fields - _time
| eval _raw="{\"CLUSTER1.COM\",\"viewSiteAsUser.hasAccess\":true}
{\"CLUSTER_VIP\":\"CLUSTER1.COM\"}"
| multikv noheader=t
| fields _raw
| rex field=_raw "(?&amp;lt;ClusterVal&amp;gt;CLUSTER[0-9]+)"&lt;/LI-CODE&gt;&lt;P&gt;Please share more events where the rex "did not work"&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 20:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Use-Eval-to-Capture-Inconsistent-key-values/m-p/742978#M240990</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-03-28T20:59:25Z</dc:date>
    </item>
  </channel>
</rss>

