Splunk Search

Using field values from a lookup to modify other field values

FelixLeh
Contributor

Screenshot 2021-01-26 at 15.33.32.png

Hey everyone,
above you can see an example of what I can expect in my work environment..
My goal is to modify the values from "tag_value" with the values of "tag_modifier" 
eg. : "True" -> "is : True"          or  "1611156456" -> "2021-01-20T16:27:36+0100" 

The "tag_modifier" field is sourced from a lookup where I want to create a similar value for every "tag_type" to easily add and manage my tag_modifiers even with great amounts of tag_types

Is there any way to do this?  ( case() macro is not an option because of the amount of tag_types)
Thanks in advance for any help!

Labels (1)
0 Karma

manjunathmeti
Champion

hi @FelixLeh ,

Try this:

| makeresults 
| eval _raw="tag_modifier;tag_type;tag_value
strftime(tag_value, \"%x %X\");tag_time;1611681945
\"is: tag_value\";tag_active;True
tag_value;tag_count;56
strptime(tag_value, \"%x %X\");tag_time;01/26/21 22:55:45" 
| multikv forceheader=1 
| fields _time, tag_modifier, tag_type, tag_value 
| eval tag_value1=replace(tag_modifier, "tag_value", tag_value) 
| rex field=tag_modifier "\"(?<format>[\w\W]+)\"\)" 
| eval tag_value=if(like(tag_modifier, "%strftime%"), strftime(tag_value, format), strptime(tag_value, format)) 
| eval tag_value=coalesce(tag_value, tag_value1)

 

If this reply helps you, an upvote/like would be appreciated. 

FelixLeh
Contributor

Even though it would technically work it's not quite what I'm looking for. My goal was to avoid if or case functions to make the formatting of the tag_value easier.. but maybe it's the only possible way. 
Thanks for your suggestion though! Maybe it'll help anyway.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...