I am trying to calculate hash on splunk log line.
How come sha256(_raw). Does not give result
Other fields sha256 works
what do you mean?
index="_audit" | eval x=sha256(_raw)
gives output pretty well, its sha256 and not shaW256...
^ Convert that comment to an answer. You're looking for sha256()
its just a typo with shaW : )
Not gonna take credit for that....
Any chance you been reading too many plays by Bernard Shaw 🙂 ?