All Apps and Add-ons
Highlighted

When is "site" generated?

New Member

I'm trying to use eval to calculate another field, using something simple

newfield = eval if(like(http_request,"%"+site+"%"),1,0)

This works fine from the search command line, but does not evaluate when I do it as an automatic field calculation, it's like the "site" field has not yet been defined and I cannot find where that is configured. Any ideas?

0 Karma
Highlighted

Re: When is "site" generated?

Communicator

Have you looked to see if 'site' field occurs earlier in the search-time order of operations? (https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/definecalcfields)

http://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Searchtimeoperationssequence

Also -- I've sometimes had to rename fields (e.g., add a z prefix) to make sure a field I need to reference is calculated prior to this calculated field.

0 Karma
Highlighted

Re: When is "site" generated?

New Member

That's part of the problem, I cannot even find where the "site" field is defined - it's not in extractions, calculated or aliases.

0 Karma
Highlighted

Re: When is "site" generated?

Communicator

Check out props.conf (search for 'site'.)

From transforms.conf in the app...
[WAsessions]
external
type = kvstore
fieldslist = _time,site,user,httpsession,httpsessionstart,httpsessionend,httpsessionpageviews,httpsessionduration,httpsessionreferrer,httpsessionreferrerdomain,httpsessionreferrerhostname,httpsessionchannel
time_field = _time
filename =

[WApages]
external
type = kvstore
fieldslist = site,httprequest
filename =

0 Karma
Highlighted

Re: When is "site" generated?

Splunk Employee
Splunk Employee

Hi

Please check out the documentation page for the app. There's some steps you need to do to configure it. The site fields comes from a lookup.

j

View solution in original post

0 Karma