Splunk Search

How to use lookup function for fuzzy matching

xsstest
Communicator

Sorry, my English is not very good.

I extracted a field named "user-agent", I also have a CSV file, the specific content is as follows:

Now,I want to use the lookup function for fuzzy matching with user-agent results. Can I do it?

for example :

user-agent=Mozilla/5.0 (Windows NT 6.2; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0

How to fuzzy match the contents of a column in a CSV file.

I expect the output of the second, three column with the result

You might suggest that I use the eval function,

But I have a lot of keywords

But I have a lot of keywords

alt text

Tags (1)
0 Karma
1 Solution

MuS
Legend

HI xsstest,

have a look at this app https://splunkbase.splunk.com/app/1843/ , this app https://splunkbase.splunk.com/app/1795/ or this app https://splunkbase.splunk.com/app/3003/ .
I haven't used any of these but it sounds like they provide a solution to your problem.

Otherwise read the wildcard match for lookups in transforms.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf - you need to look for the match_type = <string> option.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

jrmurray
Explorer

Not to revive this old thread, but to folks who visit this later with a similar question, the following app will do what OP is asking for:

https://splunkbase.splunk.com/app/5237/

MuS
Legend

HI xsstest,

have a look at this app https://splunkbase.splunk.com/app/1843/ , this app https://splunkbase.splunk.com/app/1795/ or this app https://splunkbase.splunk.com/app/3003/ .
I haven't used any of these but it sounds like they provide a solution to your problem.

Otherwise read the wildcard match for lookups in transforms.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf - you need to look for the match_type = <string> option.

Hope this helps ...

cheers, MuS

0 Karma

xsstest
Communicator

Why no one answered the question?

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...