Getting Data In

How to assign "source" during a search after a conditional statement?

ricotries
Communicator

I am creating a dashboard to show all Linux command line history per user and I would like to create an input where you can type the user and if it matches anything in a case statement, it assigns a value to "source" and runs the search.

For example, I have two sources:

source=/root/.bash_history 
source=/opt/splunk/.bash_history

I have a token $acct$ which holds the user that was typed in the input.
I wrote this search:

index=linux sourcetype=linux_cli
| eval search_source=case($acct$ == root, "/root/.bash_history", $acct$ == splunk, "/opt/splunk/.bash_history")
| search source=search_source

But this returns no results. How can I do this assignment during search?

0 Karma
1 Solution

manjunathmeti
Champion

Try this:

index=linux sourcetype=linux_cli
 | eval search_source=case("$acct$" == "root", "/root/.bash_history", "$acct$" == "splunk", "/opt/splunk/.bash_history")
 | where match(source, search_source)

OR use match:

index=linux sourcetype=linux_cli
 | eval search_source=case(match("$acct$", "root"), "/root/.bash_history", match("$acct$", "splunk"), "/opt/splunk/.bash_history")
 | where match(source, search_source)

View solution in original post

manjunathmeti
Champion

Try this:

index=linux sourcetype=linux_cli
 | eval search_source=case("$acct$" == "root", "/root/.bash_history", "$acct$" == "splunk", "/opt/splunk/.bash_history")
 | where match(source, search_source)

OR use match:

index=linux sourcetype=linux_cli
 | eval search_source=case(match("$acct$", "root"), "/root/.bash_history", match("$acct$", "splunk"), "/opt/splunk/.bash_history")
 | where match(source, search_source)

ricotries
Communicator

Neither of these worked. Just to test I'm using literal text (instead of tokens) and running it in a search. The time is set for "All Time" and there were not results.

0 Karma

manjunathmeti
Champion

Updated answer, check now. If not working post some samples of source from your data.

0 Karma

ricotries
Communicator

They both work if you place double quotes around the token:
"$acct$" == "root"

Edit your response for any one else who ends up running into this. Thank you!

manjunathmeti
Champion

That's great! I updated my answer. Thank you.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@ricotries

Can you please try this?

index=linux sourcetype=linux_cli
| eval act=$acct$
| eval search_source=case(act="root", "/root/.bash_history", act="splunk", "/opt/splunk/.bash_history") 
| where source=search_source
0 Karma

ricotries
Communicator

This did not work. It's not throwing any errors, it's just not returning anything.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...