Dashboards & Visualizations

What should I do with the spl?

minpd0309
Explorer

HI! I want to make the log below in the form of the table below. What should I do with the spl?

[Log ex.]
[2023.01.23] TYPE : UPDATE, USER : master, [ ID : jenny, TYPE- AUTH :  AB, O, B, A]

[table]

USER ID TYPE-AUTH
master jenny

AB

O

B

A

 

I did SPL as below, and the dashboard comes out as below.
HELP ME PLZ... T. T

[SPL]
| rex field=TYPE-AUTH max_match=0 "(?P<type_auth>\w+)"

USER ID TYPE-AUTH
master jenny AB
Labels (1)
0 Karma

minpd0309
Explorer

HI! @ITWhisperer I only set the rex!
Do you need any additional settings?~

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like your TYPE-AUTH field has not been extracted as you expected. How have you defined the extraction for this field?

0 Karma

minpd0309
Explorer

Please let me know if there is anything else I need to set up.

My English is weird because I turned on the translator.

0 Karma

minpd0309
Explorer

HI! @ITWhisperer I only set the rex!
Do you need any additional settings?~

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming your events look exactly like your example, you probably need to extract the TYPE-AUTH field again.

| rex "TYPE-AUTH\s*:\s*(?<TYPE_AUTH>[^\]]"
| rex field=TYPE_AUTH max_match=0 "(?P<type_auth>\w+)"
0 Karma

minpd0309
Explorer
USERIDTYPE-AUTH
masterjennyA

 

I modified it to the SPL you told me, but DASHBOARD comes out as below! T. T

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Change your dashboard to use type_auth or assign the value from this field to TYPE-AUTH

| eval TYPE-AUTH=type_auth
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...