<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: adding a field based on other fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26400#M5086</link>
    <description>&lt;P&gt;Thanks a lot for the very complete answer. I will test it right away &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2011 08:28:16 GMT</pubDate>
    <dc:creator>wsw70</dc:creator>
    <dc:date>2011-12-02T08:28:16Z</dc:date>
    <item>
      <title>adding a field based on other fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26398#M5084</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am trying to use splunk to parse nessus results. I have managed to have them loaded, parsed and I get the fields I wanted. The file general structure is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;date foo bar MS11-049: Vulnerability in the Microsoft XML Editor Could...
date foo bar Microsoft: Vulnerabilities in GDI+ Could Allow...
date foo bar Firefox 6 Multiple Vulnerabilities...
date foo bar Adobe Reader &amp;lt; 10.1...
date foo bar Adobe Flash Multiple...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;EM&gt;date&lt;/EM&gt; is the timestamp, &lt;EM&gt;foo&lt;/EM&gt; and &lt;EM&gt;bar&lt;/EM&gt; are some info and the remaining of the line is the name of the vulnerability. &lt;EM&gt;date&lt;/EM&gt;, &lt;EM&gt;foo&lt;/EM&gt;, &lt;EM&gt;bar&lt;/EM&gt; and the vulnerability are available as fields N_date, N_foo, N_bar and N_vuln.&lt;/P&gt;

&lt;P&gt;I would like to create a new field &lt;EM&gt;N_family&lt;/EM&gt; which would give the product family. In the case above this would be &lt;EM&gt;Microsoft&lt;/EM&gt; (matching &lt;CODE&gt;MS&lt;/CODE&gt; and &lt;CODE&gt;Microsoft&lt;/CODE&gt;), &lt;EM&gt;Firefox&lt;/EM&gt; (matching &lt;CODE&gt;Firefox&lt;/CODE&gt;) and &lt;EM&gt;Adobe&lt;/EM&gt; (matching &lt;CODE&gt;Adobe&lt;/CODE&gt;). &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is it possible to add such a new field to the existing list of fields extracted from the event?&lt;/LI&gt;
&lt;LI&gt;Is it possible to do it at indexing time?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I will be trying to do the same with IP addresses which match a given site (I found some useful information &lt;A href="http://splunk-base.splunk.com/answers/5916/using-cidr-in-a-lookup-table" target="_blank"&gt;here&lt;/A&gt; and hope that the mechanism above would be applicable as well, if it exists).&lt;/P&gt;

&lt;P&gt;Thank you for any pointers!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26398#M5084</guid>
      <dc:creator>wsw70</dc:creator>
      <dc:date>2020-09-28T10:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: adding a field based on other fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26399#M5085</link>
      <description>&lt;P&gt;Right I know it is not at index time, but this is the what I think realistically you are best off doing... using a csv file as a lookup. So your first step should be to extract the product family members... you could do something like...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="&amp;lt;your_source_type&amp;gt;" | rex field=N_vuln "(?P&amp;lt;N_group&amp;gt;\w+[^\d\:\-\s])" | where isnotnull(N_group) | stats count by N_group
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will show you a list of the N_group members....&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;N_group        count
Adobe           2
Firefox         1
MS              1
Microsoft       1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then you should have a manually (or it can be scripted if you like) created and maintained csv (this example I use family.csv and put it in $SPLUNK_HOME/etc/apps/search/lookups) which has the family and members, something like...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;group,family
MS,Microsoft
Microsoft,Microsoft
Adobe,Adobe
Firefox,Firefox
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then modify the command to include the lookup... such as...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="/var/tmp/test1.log" | rex field=N_vuln "(?P&amp;lt;N_group&amp;gt;\w+[^\d\:\-])" | where isnotnull(N_group) | stats count by N_group | lookup family.csv group as N_group OUTPUT family as N_family
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And then you should have the &lt;CODE&gt;N_family&lt;/CODE&gt; field you desire.&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;P.S Please note, that you don't need to keep the "stats" command as this is just for demo to show your values are working.&lt;/P&gt;

&lt;P&gt;P.P.S... I think this is better, as it is not a static format, such as IP addresses. So you are not committing any changes which could end being faulty to the index, which could require cleaning the index. You could probably save this as saved search to call on, so you don't have to have the whole string.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2011 16:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26399#M5085</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2011-12-01T16:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: adding a field based on other fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26400#M5086</link>
      <description>&lt;P&gt;Thanks a lot for the very complete answer. I will test it right away &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2011 08:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/adding-a-field-based-on-other-fields/m-p/26400#M5086</guid>
      <dc:creator>wsw70</dc:creator>
      <dc:date>2011-12-02T08:28:16Z</dc:date>
    </item>
  </channel>
</rss>

