Splunk Search

How do I edit my real-time search to add a value to events that are missing a certain field?

splunker9999
Path Finder

Hi

We have the search below which gives us the count of all our URLs in events in real-time, but we have a few events where URL is missing.

Now we need to assign a certain URL value to those events which do not have a URL, but subsearch is not working for this as it is a real-time search.

For ex: We have events where URL is missing, but have the value "EXPRESS". We need to filter those events by this value and assign them a separate URL value called "EXPRESS.com". Can someone please suggest how we can do this?

Below is our search we used:

index=datapower host="10.71.8.170"  NOT URL=https://raly.com tag=prod  
|eval URL=case(URL="https://gita.com","ATON",URL="https://services.com",
"SERVICES",URL="https://soap.com","RAN",URL="https://www.care.com",
"CARE",URL="https://post.com","Post",
URL="http://get.com","GET",URL="https://master.com","Master",1=1,"Others")
|stats count(datapower_response_time) as count by URL|

For the search above, we need to add events that contain "Express" to EXPRESS.COM (as we don't have URL for these events)

Thanks..

0 Karma

woodcock
Esteemed Legend

If I am understanding you correctly (highly questionable), you can use this to add .com if it does not already exist.

... | eval URL=if((matc(URL, "\.com$")), URL, URL + ".com") ...
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...