Splunk Search

Extract value from multiple events that have different fields?

pmcfadden91
Path Finder

Below is my query which list about 80 events grouped by a certain ID (488e5185-42d7-4eec-bcb5-43590ae751a0).
The events have different field names for the same ID (ASAPLocateID, TransID, locate, clientLocateId domain="GLR">488e5185-42d7-4eec-bcb5-43590ae751a0</ns0:clientLocateId). How can I extract this ID and any others into a field regardless of the different host, source, or sourcetype?

index="gfs_cft_neo" OR index="gfs_sbl_al" source!="*performance*" "488e5185-42d7-4eec-bcb5-43590ae751a0"| reverse | streamstats window=1 global=f current=t first(source) as p_source count as Transition | eval transition_time = if(p_source == source, _time, -1 ) | where transition_time &gt; -1 | streamstats count as Transition | delta transition_time AS transition_duration | rex field=source ".*/(?&lt;Component&gt;.*).log"| table Transition, Component, transition_duration

0 Karma
1 Solution

woodcock
Esteemed Legend

With the coalesce command, like this:

index="gfs_cft_neo" OR index="gfs_sbl_al" source!="performance" "488e5185-42d7-4eec-bcb5-43590ae751a0"| eval NormalizedID=coalesce(ASAPLocateID, TransID, locate, clientLocateId)

Then you do your downstream work with NormalizedID.

View solution in original post

0 Karma

woodcock
Esteemed Legend

With the coalesce command, like this:

index="gfs_cft_neo" OR index="gfs_sbl_al" source!="performance" "488e5185-42d7-4eec-bcb5-43590ae751a0"| eval NormalizedID=coalesce(ASAPLocateID, TransID, locate, clientLocateId)

Then you do your downstream work with NormalizedID.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...