Splunk Search

How to use lookup function for fuzzy matching

xsstest
Communicator

Sorry, my English is not very good.

I extracted a field named "user-agent", I also have a CSV file, the specific content is as follows:

Now,I want to use the lookup function for fuzzy matching with user-agent results. Can I do it?

for example :

user-agent=Mozilla/5.0 (Windows NT 6.2; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0

How to fuzzy match the contents of a column in a CSV file.

I expect the output of the second, three column with the result

You might suggest that I use the eval function,

But I have a lot of keywords

But I have a lot of keywords

alt text

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

HI xsstest,

have a look at this app https://splunkbase.splunk.com/app/1843/ , this app https://splunkbase.splunk.com/app/1795/ or this app https://splunkbase.splunk.com/app/3003/ .
I haven't used any of these but it sounds like they provide a solution to your problem.

Otherwise read the wildcard match for lookups in transforms.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf - you need to look for the match_type = <string> option.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

jrmurray
Explorer

Not to revive this old thread, but to folks who visit this later with a similar question, the following app will do what OP is asking for:

https://splunkbase.splunk.com/app/5237/

MuS
SplunkTrust
SplunkTrust

HI xsstest,

have a look at this app https://splunkbase.splunk.com/app/1843/ , this app https://splunkbase.splunk.com/app/1795/ or this app https://splunkbase.splunk.com/app/3003/ .
I haven't used any of these but it sounds like they provide a solution to your problem.

Otherwise read the wildcard match for lookups in transforms.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf - you need to look for the match_type = <string> option.

Hope this helps ...

cheers, MuS

0 Karma

xsstest
Communicator

Why no one answered the question?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...