<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dealing with duplicate variables after tranaction command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127303#M34520</link>
    <description>&lt;P&gt;Yes, well. These operations will not change the event that is presented on screen (which is stored in the &lt;CODE&gt;_raw&lt;/CODE&gt; field). However, they will change the extracted field values, so what happens if you run the following;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=sonicwall TemplateID=257 OR TemplateID=262 | transaction session_id startswith=TemplateID=257 | head 2 |eval dest_mac=mvfilter(dest_mac !="00:00:00:00:00:00") | table session_id dest_mac&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2014 22:13:53 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2014-01-28T22:13:53Z</dc:date>
    <item>
      <title>dealing with duplicate variables after tranaction command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127300#M34517</link>
      <description>&lt;P&gt;I am working with IPFix data from a firewall. The first template returns the flow information. That is stuff like Source IP, Destination IP, Flow ID. The second template returns URL related data. Using the trasaction command I can correlate the events based on the Flow ID. In both templates are the dest_mac. The trouble is one of the templates always returns the MAC of 00:00:00:00:00:00 which is bad data. I would like to filter that data out any way possible. &lt;/P&gt;

&lt;P&gt;How do I filter it?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 22:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127300#M34517</guid>
      <dc:creator>jalfrey</dc:creator>
      <dc:date>2014-01-27T22:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: dealing with duplicate variables after tranaction command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127301#M34518</link>
      <description>&lt;P&gt;If you want to filter it out before it is even indexed, you could use the anonymization techniques discussed in the docs (see below) to remove the faulty MAC before it even reaches the index;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Anonymizedatausingconfigurationfiles"&gt;http://docs.splunk.com/Documentation/Splunk/6.0.1/Data/Anonymizedatausingconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you want to replace it during search, i.e. after the &lt;CODE&gt;transaction&lt;/CODE&gt;, you can use the following (assuming the multivalued field is called MAC;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | transaction FlowID | eval MAC=mvfilter(MAC != 00:00:00:00:00:00) |
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or, if they always come in the same order (in this case the good MAC always come before the bad)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | transaction FlowID | eval MAC=mvindex(MAC,0) 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;if the bad always come before the good, use &lt;CODE&gt;mvindex(MAC,1)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;See more here;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/CommonEvalFunctions"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/CommonEvalFunctions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2014 00:23:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127301#M34518</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-01-28T00:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: dealing with duplicate variables after tranaction command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127302#M34519</link>
      <description>&lt;P&gt;search:&lt;BR /&gt;
index=sonicwall TemplateID=257 OR TemplateID=262 | transaction session_id startswith=TemplateID=257 | eval dest_mac=mvfilter(dest_mac !="00:00:00:00:00:00")&lt;BR /&gt;
returns:&lt;BR /&gt;
TemplateID=257 session_id=2149159280 src_mac=00:50:56:a1:75:51 dest_mac=00:00:00:00:00:00 src_ip=192.168.1.1 dest_ip=192.168.1.254 initiator_GW-IP_Addr=0.0.0.0 responder_GW-IP_Addr=0.0.0.0 src_int=19 src_port=63843 dest_port=443 init_to_resp_pkts=8 init_to_resp_octets=3260 init_to_resp_delta_pkts=8 init_to_resp_delta_octets=3260 start_time=2014-01-28 09:29:12 end_time=1969-12-31 16:00:00 tcp_flag=1 protocol=6 app_id=49178&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127302#M34519</guid>
      <dc:creator>jalfrey</dc:creator>
      <dc:date>2020-09-28T15:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: dealing with duplicate variables after tranaction command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127303#M34520</link>
      <description>&lt;P&gt;Yes, well. These operations will not change the event that is presented on screen (which is stored in the &lt;CODE&gt;_raw&lt;/CODE&gt; field). However, they will change the extracted field values, so what happens if you run the following;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=sonicwall TemplateID=257 OR TemplateID=262 | transaction session_id startswith=TemplateID=257 | head 2 |eval dest_mac=mvfilter(dest_mac !="00:00:00:00:00:00") | table session_id dest_mac&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2014 22:13:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dealing-with-duplicate-variables-after-tranaction-command/m-p/127303#M34520</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-01-28T22:13:53Z</dc:date>
    </item>
  </channel>
</rss>

