Splunk Search

How to standardize similar words?

aa0
Path Finder

Hi all,

I have two similar words that giving the same meaning. How can I standardize them into one value to prevent inconsistencies in result but at the same time keep initial subcontent for both words?

Here's the detail:

app= AOutlook, Outlook..etc

index=XXX app=XX...| eval Outlook=mvappend(AOutlook, Outlook)|table app action...

expected result:

app           |   action ....

Outlook       Not found

Outlook       Completed

previous query for append doesn't work, any alternative will be appreciated!

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which "words" are you trying to "standardize"? Are the words values from a field e.g. app or field names?

It would be helpful if you could share some sample events (in a code block </>, anonymised of course).

0 Karma

aa0
Path Finder

Some of the app names consist inside the app category- for instance AOutlook and Outlook are basically represent the same category app name, hence I need both of the field names but only with filed1-Outlook field2-Outlook instead of field1-AOutlook field2-Outlook (standard name for both fields).

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share some of your events?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...