Splunk Search

How to standardize similar words?

aa0
Path Finder

Hi all,

I have two similar words that giving the same meaning. How can I standardize them into one value to prevent inconsistencies in result but at the same time keep initial subcontent for both words?

Here's the detail:

app= AOutlook, Outlook..etc

index=XXX app=XX...| eval Outlook=mvappend(AOutlook, Outlook)|table app action...

expected result:

app           |   action ....

Outlook       Not found

Outlook       Completed

previous query for append doesn't work, any alternative will be appreciated!

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which "words" are you trying to "standardize"? Are the words values from a field e.g. app or field names?

It would be helpful if you could share some sample events (in a code block </>, anonymised of course).

0 Karma

aa0
Path Finder

Some of the app names consist inside the app category- for instance AOutlook and Outlook are basically represent the same category app name, hence I need both of the field names but only with filed1-Outlook field2-Outlook instead of field1-AOutlook field2-Outlook (standard name for both fields).

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share some of your events?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...