Splunk Search

Dynamically analyze fields?

sf_user_199
Path Finder

I have some data that looks like this:

priority=INFO thread= location= line= field1=OK,field2=OK,field3=OK....field45=OK

What I need to do is analyze field1 through field45 (the number may change) to see if they all equal 'OK'. If not 'OK' then alert. The field names do not all start with the same thing (so no field*).

I can, however, do something like this in the search:

| rex "(?i)line=[\d]\w(?P.*)" | fields host,kv_pairs_to_check| makemv kv_pairs_to_check delim=","

This is kinda giving me the data I want, but not really, and I haven't been able to figure out how to check every kv pair if the value is 'OK' for all of them.

Tags (2)
1 Solution

fk319
Builder

how about instead of putting them in a seperate field, use the same field.?


at the moment I am not sure, but if you know the total and the number of OK's are not the same then error, or regex out the OK and report what is left over?


Probably not very helpfull, but maybe someone else can expand on this idea...

View solution in original post

0 Karma

fk319
Builder

how about instead of putting them in a seperate field, use the same field.?


at the moment I am not sure, but if you know the total and the number of OK's are not the same then error, or regex out the OK and report what is left over?


Probably not very helpfull, but maybe someone else can expand on this idea...

0 Karma

sf_user_199
Path Finder

I won't know the exact numbers, so counting is out. Looking for =[^O] is a great idea, however. I'm going to play around with that...

0 Karma

fk319
Builder

ok, I was think about this a different way, could you take your list of fields as just one field and search to see if you have a regex of '=[^O]' ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...