Splunk Search

Urldecode _raw at index time

Ant1D
Motivator

Hi,

I am aware that it can be done at search-time via props.conf:
[sourcetype]
EVAL-_raw = urldecode(_raw)

Is it possible to urldecode(_raw) at index time in Splunk? I want to perform a urldecode on _raw with the result being assigned to the _raw which will then be indexed by Splunk.

Is there a RegEx that can decode any url?
Thanks in advance for your help.

0 Karma

woodcock
Esteemed Legend

You can use SEDCMD to transform the raw text on the way in but the only facilities to add index-time fields require values that are either a hard-coded string or a contiguous subset of the raw data.

0 Karma

micahkemp
Champion

You may want to look into using a modular input for this.

link text

Modular input use cases

Unique use cases might require a modular or scripted input. Here are some typical examples.

    Stream results from a command, such as vmstat and iostat.
    Query a database, web service, or API.
    Reformat complex data.
    Handle sensitive information more securely.
    Handle special characters in inputs.
0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...