Splunk Search

XML Conditional suffix prefix

weidertc
Contributor

I have an input text and input dropdown that both need to allow blank value.  They cannot be null since the token must be set or the queries that use it won't run.  I need a prefix and suffix both wildcards only when there's a value, and to use a single wildcard (*) in its absence.

I tried this, but the prefix and suffix keep multiplying and soon i have 10 suffixes and 10 prefixes.

here's the input text:

 

      <prefix/>
      <suffix/>
      <change>
        <eval token="assetFilter">if(len($assetFilter$)&gt;0, "*" . $assetFilter$ . "*", "*")</eval>
      </change>

 

after entering, removing, entering, removing values, the suffix and prefix kept multiplying and eventually looked like this

****tag=****

 

Here's the other one, a dropdown of macros so it needs the ` char with the wildcard, after selecting, unselecting, selecting, and unselecting values in the dropdown.

 

        <change>
          <eval token="asset">if(len($asset$)&gt;0, "*`" . $asset$ . "`*", "*")</eval>
        </change>

 

*`*`*`*`*`*`*`*`*`*`*`*`*`*`*`ED_ENDI_Asdf`*`*`*`*`*`*`*`*`*`*`*`*`*`*`*

 

How can I use prefix and suffix conditionally a little better or in a way that works?

-c

 

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried setting a different token e.g. 

<eval token="assetFilter2">if(len($assetFilter$)&gt;0, "*" . $assetFilter$ . "*", "*")</eval>
0 Karma

weidertc
Contributor

Yea I tried that.  it makes no difference.

I give up on this.  It's taking too much time.

thanks for your help.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...