Splunk Search

How can I use sha1 in my Splunk search

pk87
Engager

We save hash values from our ids and I want to search for them. I would expected I can do it this way:

index=blub id=sha1("11122233") 

But unfurtonaly it doesn't work. Also other attemps failed (for exampe to eval it first in a new variable). If I just use the sha1 it return the correct value, but somehow it doesn't work in the search. 


Can anybody help here or has suggestion. 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
index=blub
| id=sha1("11122233")
| where 'properties.id'=id

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=blub
| where id=sha1("11122233")
0 Karma

pk87
Engager

I tried this, but don' get results

 

index=blub sourcetype=blub:nadev | where properties.id = sha1("SNL123456789454651")

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

That would seem to suggest that properties.id does not contain the sha1 of "SNL123456789454651", at least not as the only thing in it.

Do you have some example event you can share which are not being found when they should?

0 Karma

pk87
Engager

image.pngimage.pngimage.png

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=blub
| id=sha1("11122233")
| where 'properties.id'=id
0 Karma

pk87
Engager

I am not able to find anything with the where statement. Even if I use directly the hash value.

 

So this works:

index=rtt properties.vin = "d7a4acc844c8176009371c65c63bd07c929d4738"

but this doesn't:

index=rtt | where properties.vin = "d7a4acc844c8176009371c65c63bd07c929d4738"

0 Karma

pk87
Engager

I missed this part. now it works!

 

index=rtt | where 'properties.vin' = sha1("SNL23456789185206")

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try with the field name in single quotes (as I showed in my example)

0 Karma

pk87
Engager

I missed this part. now it works!

 

index=rtt | where 'properties.vin' = sha1("SNL23456789185206")

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...