Hi,
I am aware that it can be done at search-time via props.conf:
[sourcetype]
EVAL-_raw = urldecode(_raw)
Is it possible to urldecode(_raw) at index time in Splunk? I want to perform a urldecode on _raw with the result being assigned to the _raw which will then be indexed by Splunk.
Is there a RegEx that can decode any url?
Thanks in advance for your help.
You can use SEDCMD
to transform the raw text on the way in but the only facilities to add index-time fields require values that are either a hard-coded string or a contiguous subset of the raw data.
You may want to look into using a modular input for this.
Modular input use cases
Unique use cases might require a modular or scripted input. Here are some typical examples.
Stream results from a command, such as vmstat and iostat.
Query a database, web service, or API.
Reformat complex data.
Handle sensitive information more securely.
Handle special characters in inputs.