Splunk Search

How to standardize similar words?

aa0
Path Finder

Hi all,

I have two similar words that giving the same meaning. How can I standardize them into one value to prevent inconsistencies in result but at the same time keep initial subcontent for both words?

Here's the detail:

app= AOutlook, Outlook..etc

index=XXX app=XX...| eval Outlook=mvappend(AOutlook, Outlook)|table app action...

expected result:

app           |   action ....

Outlook       Not found

Outlook       Completed

previous query for append doesn't work, any alternative will be appreciated!

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which "words" are you trying to "standardize"? Are the words values from a field e.g. app or field names?

It would be helpful if you could share some sample events (in a code block </>, anonymised of course).

0 Karma

aa0
Path Finder

Some of the app names consist inside the app category- for instance AOutlook and Outlook are basically represent the same category app name, hence I need both of the field names but only with filed1-Outlook field2-Outlook instead of field1-AOutlook field2-Outlook (standard name for both fields).

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share some of your events?

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...