Splunk Search

How to standardize similar words?

aa0
Path Finder

Hi all,

I have two similar words that giving the same meaning. How can I standardize them into one value to prevent inconsistencies in result but at the same time keep initial subcontent for both words?

Here's the detail:

app= AOutlook, Outlook..etc

index=XXX app=XX...| eval Outlook=mvappend(AOutlook, Outlook)|table app action...

expected result:

app           |   action ....

Outlook       Not found

Outlook       Completed

previous query for append doesn't work, any alternative will be appreciated!

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which "words" are you trying to "standardize"? Are the words values from a field e.g. app or field names?

It would be helpful if you could share some sample events (in a code block </>, anonymised of course).

0 Karma

aa0
Path Finder

Some of the app names consist inside the app category- for instance AOutlook and Outlook are basically represent the same category app name, hence I need both of the field names but only with filed1-Outlook field2-Outlook instead of field1-AOutlook field2-Outlook (standard name for both fields).

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share some of your events?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...