Splunk Search

Urldecode _raw at index time

Ant1D
Motivator

Hi,

I am aware that it can be done at search-time via props.conf:
[sourcetype]
EVAL-_raw = urldecode(_raw)

Is it possible to urldecode(_raw) at index time in Splunk? I want to perform a urldecode on _raw with the result being assigned to the _raw which will then be indexed by Splunk.

Is there a RegEx that can decode any url?
Thanks in advance for your help.

0 Karma

woodcock
Esteemed Legend

You can use SEDCMD to transform the raw text on the way in but the only facilities to add index-time fields require values that are either a hard-coded string or a contiguous subset of the raw data.

0 Karma

micahkemp
Champion

You may want to look into using a modular input for this.

link text

Modular input use cases

Unique use cases might require a modular or scripted input. Here are some typical examples.

    Stream results from a command, such as vmstat and iostat.
    Query a database, web service, or API.
    Reformat complex data.
    Handle sensitive information more securely.
    Handle special characters in inputs.
0 Karma
Get Updates on the Splunk Community!

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...