Splunk Cloud Platform

How to check for underscore in field values?

Splunkerninja
Path Finder

Hi,

I am checking for underscore in field values and if it present then capture that value.

For Example: if name has underscore in it then value should get assigned to APP field and if it does not have underscore in it then value should get assigned to Host field

name         APP           Host

ftr_score ftr-score  NA

terabyte   NA              terabyte

I have tried using case and like statement but it does not work as expected

 

0 Karma
1 Solution

bharathkumarnec
Contributor

@Splunkerninja there are many way to achieve this, for example like below:

| makeresults
| eval name="ft_name_1"
| eval underscorematch=if(match(name,".\_."),"Yes","No")
| eval name_value=if(underscorematch="Yes",name,"NA")
| table name underscorematch name_value

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your example seems to change the underscore to a hyphen (I have assumed that this is a typo). Also, your criteria is not very precise, so I have assumed that you mean not an underscore, followed by an underscore, followed by not an underscore somewhere in the name.

| eval APP=if(match(name,"[^_]_[^_]"),name,null())
| eval Host=if(match(name,"[^_]_[^_]"),null(),name)

 You may need to adjust the match expression if the criteria I have  used is not what you meant. 

bharathkumarnec
Contributor

@Splunkerninja there are many way to achieve this, for example like below:

| makeresults
| eval name="ft_name_1"
| eval underscorematch=if(match(name,".\_."),"Yes","No")
| eval name_value=if(underscorematch="Yes",name,"NA")
| table name underscorematch name_value

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...