Splunk Search

Detecting keywords from another search in a field from other search

tirusplunk
Engager

Hi Guys,

I have a requirement like this. In a search I am getting a field like
ExtraInfo Count
User-Gmail-GoogleChrome 6
Inbox-Yahoo! Mail 3
.....

In another I have keywords like Gmail,Yahoo! Mail,...etc.

I want to write a query which gives me the output like this.

Keyword Count
Gmail 6
Yahoo! Mail 3

Could you please help me in this regard?

0 Karma

somesoni2
Revered Legend

Try this

<first search giving fields ExtraInfo,Count> | fields ExtraInfo, Count | eval joinfield=1
| join type=left max=0 joinfield [search <second search giving fields Keyword> | fields Keyword | eval joinfield=1] | eval shouldInclude=if(like(ExtraInfo,"%".Keyword."%"),"Yes","No") | where shouldInclude="Yes" | fields Keyword, Count
0 Karma

tirusplunk
Engager

ExtraInfo!=ExtraInfo|eval X=case(ExtraInfo LIKE "%Gmail%","Gmail",ExtraInfo LIKE "%Outlook Web App%","Outlook Web App",ExtraInfo LIKE "%Yahoo! Mail%","Yahoo! Mail")

I could think of this. But can I manage this big case statement(this case statement may grow) like an event-type or something else in my splunk?

0 Karma

HiroshiSatoh
Champion

Configuration of the Lookup table files and Lookup definitions are required.


.....|join ExtraInfo[ | inputlookup lookup_tbl]|table Keyword,Count

ExtraInfo,Keyword
"User-Gmail-GoogleChrome","Gmail"
"User-Gmail-GoogleChromeXXX","Gmail"
"User-Gmail-GoogleChromeYYY","Gmail"
"Inbox-Yahoo! Mail","Yahoo! Mail"
"Inbox-Yahoo! MailXXX","Yahoo! Mail"
"Inbox-Yahoo! MailYYY","Yahoo! Mail"

0 Karma

HiroshiSatoh
Champion

Custom field cannot be edited without a LOOKUP?

....|rex field=ExtraInfo "-(?.*)$"|table Keyword


Gmail-GoogleChrome
Yahoo! Mail

0 Karma

tirusplunk
Engager

Can I place only keywords in lookup table instead of both ExtraInfo and Keyword?

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...