Splunk Search

How to use calculated field with url?

a_naoum
Path Finder

Hello,

I'm trying to use calculated field on data with url field. Simple doesn't work. Even a very simple 'upper(url)' doesn't work.
If I'm doing |eval upper(url) it works perfect.
Is there any known restriction which I didn't see somewhere in the documentation?

Please note that the search is done on 7.0.3 fresh installation (literally nothing installed)

0 Karma
1 Solution

a_naoum
Path Finder

Unfortunately for me (because is kind of shame) I found the issue and it was with the browser sessions. By luck closing and re-opening the browser all my changes were working which is not ideal

View solution in original post

0 Karma

a_naoum
Path Finder

Unfortunately for me (because is kind of shame) I found the issue and it was with the browser sessions. By luck closing and re-opening the browser all my changes were working which is not ideal

0 Karma

DavidHourani
Super Champion

Hi @a_naoum,

This is due to the permissions of your app and your calculated field and whether the configuration is set to private, app or global.

If you created your calculated field in app A and this app doesn't export its configuration then you won't be able to see that calculated field in app B or search app. Same if you created it with user X and the permissions are set to private, then user Y won't be able to see it.

Please check the configurations and make sure you're in the right app when testing your field.

Refer here for basic permission configs :
https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Manageknowledgeobjectpermissions

Cheers,
David

0 Karma

a_naoum
Path Finder

I done the changes on props.conf of the app as I mention to someone, so in that case there is no permissions issue.
Anyway, case solved. Browser

0 Karma

somesoni2
Revered Legend

Is the url an extracted field?? Do you see it in field sidebar?

0 Karma

a_naoum
Path Finder

yes, it is. The specific events are simple KV with '=' separated fields

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@a_naoum - Please clarify first part your question, where you are saying upper(url) is not working?

0 Karma

a_naoum
Path Finder

correct. I done the same via GUI and props.conf. If I do the same 'upper' on a different field, it works. It is hard to miss the field name (it is just... url)

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Is it not working in props.conf or in search or in datamodel?

0 Karma

a_naoum
Path Finder

I said not. Datamodel is not used but I don't need to for now.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Can you tell where url field is coming from? If url it self is evaluated somewhere else in props.conf this will not work as all eval executes in parallel.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...