Splunk Search

How do I edit my real-time search to add a value to events that are missing a certain field?

splunker9999
Path Finder

Hi

We have the search below which gives us the count of all our URLs in events in real-time, but we have a few events where URL is missing.

Now we need to assign a certain URL value to those events which do not have a URL, but subsearch is not working for this as it is a real-time search.

For ex: We have events where URL is missing, but have the value "EXPRESS". We need to filter those events by this value and assign them a separate URL value called "EXPRESS.com". Can someone please suggest how we can do this?

Below is our search we used:

index=datapower host="10.71.8.170"  NOT URL=https://raly.com tag=prod  
|eval URL=case(URL="https://gita.com","ATON",URL="https://services.com",
"SERVICES",URL="https://soap.com","RAN",URL="https://www.care.com",
"CARE",URL="https://post.com","Post",
URL="http://get.com","GET",URL="https://master.com","Master",1=1,"Others")
|stats count(datapower_response_time) as count by URL|

For the search above, we need to add events that contain "Express" to EXPRESS.COM (as we don't have URL for these events)

Thanks..

0 Karma

woodcock
Esteemed Legend

If I am understanding you correctly (highly questionable), you can use this to add .com if it does not already exist.

... | eval URL=if((matc(URL, "\.com$")), URL, URL + ".com") ...
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...