Splunk Search

check if stringa in stingb

mcohen13
Loves-to-Learn

how can i make a case condition to check if StingA is in StringB?

for example StingA is "xxx.com." StingB is: "a.xxx.com."

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Try this:

... | eval match=if(like(fieldB,fieldA),1,0) | search match=1
0 Karma

mcohen13
Loves-to-Learn

if the list of domains are not in a field but in a lookup table, how does that change the query?

for example:
i have a list of domain in a lookup table
and i have a list of domain in a field

and i want to check if the list of domains in the field are in the lookup table

0 Karma

jkat54
SplunkTrust
SplunkTrust

In that case...

... | rename domain as domainFromIndex 
| inputlookup lookupName domain as domain OUTPUTNEW domainFromLookup
| eval match=if(domainFromIndex=domainFromLookup,1,0)
| where match=1
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...