Splunk Search

Eval field value evaluating correctly, but has no impact when used later down the road in the search query

des_esse_err
Explorer

It's a simple search query. It needs to find events containing a file name which will change every month.

The eval command should return YYmm* (1412*).

This query works
The eval field signatureVersionCriteria has been replaced -hard coded- with the value it should hold.
The field values shown in a table do indeed display "1412*" for the signatureVersionCriteria field.

index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") + "*" | search signature_version="1412*"| table signature_version, signatureVersionCriteria

This query does not work
It returns nothing.

index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") + "*" | search signature_version = signatureVersionCriteria | table signature_version, signatureVersionCriteria

Went through quite a lots of posts, similar to this, but could not figure it out.
Many thanks.
D

Tags (1)
0 Karma
1 Solution

aholzer
Motivator

Try the following:

index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") | where like(signature_version,signatureVersionCriteria."%") | table signature_version, signatureVersionCriteria

View solution in original post

aholzer
Motivator

Try the following:

index=xxx_app_sep | eval signatureVersionCriteria = strftime(now(), "%y%m") | where like(signature_version,signatureVersionCriteria."%") | table signature_version, signatureVersionCriteria

des_esse_err
Explorer

Hello! Many thanks it does indeed work.

0 Karma

somesoni2
Revered Legend

Hi David,

If Aleksander's answer has solved your problem, please accept the answr by clicking on the tick-mark+Accept button below the answer. This will help other users with similar problem to identify the correct solution and you both will get points.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...