Knowledge Management

Eventtype Definition: Search by Field Value length

gpburgett
Splunk Employee
Splunk Employee

Similarly, I want to make a group/eventtype of events from a certain sourcetype where the LOGINID values are all 12 characters long. I can get these events out using pipes and regexes, but then eventtypes does not accept search queries with pipes. Is there a way to extract the LOGINID length as a seperate field that I can use to search on in my eventtype query?

Tags (1)
0 Karma
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

As in http://answers.splunk.com/questions/10145/case-sensitivity-in-eventtype-searches/10197#10197, you should be able to coerce your regex to extract fields that are only of a certain length.

View solution in original post

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

As in http://answers.splunk.com/questions/10145/case-sensitivity-in-eventtype-searches/10197#10197, you should be able to coerce your regex to extract fields that are only of a certain length.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...