Splunk Search

Urldecode _raw at index time

Ant1D
Motivator

Hi,

I am aware that it can be done at search-time via props.conf:
[sourcetype]
EVAL-_raw = urldecode(_raw)

Is it possible to urldecode(_raw) at index time in Splunk? I want to perform a urldecode on _raw with the result being assigned to the _raw which will then be indexed by Splunk.

Is there a RegEx that can decode any url?
Thanks in advance for your help.

0 Karma

woodcock
Esteemed Legend

You can use SEDCMD to transform the raw text on the way in but the only facilities to add index-time fields require values that are either a hard-coded string or a contiguous subset of the raw data.

0 Karma

micahkemp
Champion

You may want to look into using a modular input for this.

link text

Modular input use cases

Unique use cases might require a modular or scripted input. Here are some typical examples.

    Stream results from a command, such as vmstat and iostat.
    Query a database, web service, or API.
    Reformat complex data.
    Handle sensitive information more securely.
    Handle special characters in inputs.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...