Splunk Search

How to output from lookup table if a field value is included anywhere within table field

epw0rrell
Path Finder

I know how to use eval and if statements to pull fields that contain a %.value.% but how can I use this when running a search | lookup and output fields that contain a value of a field within the search?  Let me know if you need an example search or more context.  Thanks to anyone that can help me with this.

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

An example and more context would be helpful

0 Karma

epw0rrell
Path Finder

I have one index of alerts containing a field named "alertDomain" with values like "domain.com."

I have a lookup table with urls sent within emails with values like http://www.domain.com/otherplaces 

I would like to run a search like this:

index=alerts | lookup emailURLs.csv emailURL as alertDomain OUTPUT emailURL as phishingURL | table phishingURL

but I know this won't work because the fields will not match.  I need to OUTPUT the emailURL if it simply contains the value within alertDomain.

Is this a bit better?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you add another column to the emailURLs.csv file with the domain part of the URL so that you can get a match?

0 Karma

epw0rrell
Path Finder

Unfortunately there is only a URL field within the logs.  Unless I can use a clever field extraction on the URL, I would need to go about it from this direction.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...