Splunk Search

Custom calculated Field-Extraction

meenal901
Communicator

Hi,

I have a data of the form:
Source,Date,Time
Source1,20120904,000000
Source3,20120904,000000
Source1,20120904,000000
Source4,20120904,000000
Source2,20120904,000000
Source3,20120904,000000
Source4,20120904,000000
Source2,20120904,000000

When i upload this file, i want to sort is based on column "Source" and add a custom column called "Unique_ID" which will have value of time+1 for same Source. Effectively, the data should look like:

Source,Date,Time
Source1,20120904,000001
Source1,20120904,000002
Source2,20120904,000001
Source2,20120904,000002
Source3,20120904,000001
Source3,20120904,000002
Source4,20120904,000001
Source4,20120904,000002

What regex should be written to props.conf and transforms.conf to do the same?

Tags (1)
0 Karma
1 Solution

meenal901
Communicator

I resolved this by using eventstats at search time. Assigned a unique ID at run-time.

View solution in original post

0 Karma

meenal901
Communicator

I resolved this by using eventstats at search time. Assigned a unique ID at run-time.

0 Karma

Ayn
Legend

You could use the _indextime field to check when events were indexed, and then use that (if I understood your scenario correctly).

0 Karma

meenal901
Communicator

Yes i understand the limitation of regex. The data is in a bucket of 15 minutes. I need a way to co-relate events of a source with another. A unique key at the time of adding data. But couldn't find.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Regular expressions can neither sort nor count nor do maths. For that you need a more powerful language, such as a scripted input that does this work for you.

What's the ultimate goal you're trying to achieve here?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...