Dashboards & Visualizations

What should I do with the spl?

minpd0309
Explorer

HI! I want to make the log below in the form of the table below. What should I do with the spl?

[Log ex.]
[2023.01.23] TYPE : UPDATE, USER : master, [ ID : jenny, TYPE- AUTH :  AB, O, B, A]

[table]

USER ID TYPE-AUTH
master jenny

AB

O

B

A

 

I did SPL as below, and the dashboard comes out as below.
HELP ME PLZ... T. T

[SPL]
| rex field=TYPE-AUTH max_match=0 "(?P<type_auth>\w+)"

USER ID TYPE-AUTH
master jenny AB
Labels (1)
0 Karma

minpd0309
Explorer

HI! @ITWhisperer I only set the rex!
Do you need any additional settings?~

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like your TYPE-AUTH field has not been extracted as you expected. How have you defined the extraction for this field?

0 Karma

minpd0309
Explorer

Please let me know if there is anything else I need to set up.

My English is weird because I turned on the translator.

0 Karma

minpd0309
Explorer

HI! @ITWhisperer I only set the rex!
Do you need any additional settings?~

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming your events look exactly like your example, you probably need to extract the TYPE-AUTH field again.

| rex "TYPE-AUTH\s*:\s*(?<TYPE_AUTH>[^\]]"
| rex field=TYPE_AUTH max_match=0 "(?P<type_auth>\w+)"
0 Karma

minpd0309
Explorer
USERIDTYPE-AUTH
masterjennyA

 

I modified it to the SPL you told me, but DASHBOARD comes out as below! T. T

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Change your dashboard to use type_auth or assign the value from this field to TYPE-AUTH

| eval TYPE-AUTH=type_auth
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...