Splunk Search

Help with search using eval and table?

oh_sechang
New Member

 

 

index="hx_vm" LogName="Microsoft-Windows-Sysmon/Operational" "EventCode=11" ComputerName=DESKTOP-933JR8B
| eval {name} = replace("C:\Windows\SysWOW64\OneDriveSetup.exe","\", "\\")
| search Image = name
| table _time, TargetFilename

 

 

The variable usage part is difficult.

Labels (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Where is the question?  Three detail you need in a post: how does the data look like, what is it that you expect as result, what is the logic between data and expected result; if you post sample code, explain the result you get and why it doesn't meet requirements.

Looking at your sample code, I guess you do not mean | search Image = "name", because that's exactly what the code means.  Anything on the right of an equal sign  in a search command is a string.  Try

index="hx_vm" LogName="Microsoft-Windows-Sysmon/Operational" "EventCode=11" ComputerName=DESKTOP-933JR8B
| eval name = replace("C:\Windows\SysWOW64\OneDriveSetup.exe","\", "\\")
| where Image == name
| table _time, TargetFilename

 

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...