Splunk Search

case command

DataOrg
Builder

i want case command to match case where abc = hhh and after word should be same as present as it is
abc
abc
efg
ffh

0 Karma
1 Solution

niketn
Legend

[Updated Answer]
With exact match and run anywhere search query

Ok then you need the following to be added to your existing search

| makeresults
| eval type="abc,xyzabc,abcdef,xyzabcdef"
| makemv type delim="," 
| mvexpand type
| replace "abc" with "123" in type

Or else

| makeresults
| eval type="abc,xyzabc,abcdef,xyzabcdef"
| makemv type delim="," 
| mvexpand type
| eval type=replace(type,"^abc$","123")
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

[Updated Answer]
With exact match and run anywhere search query

Ok then you need the following to be added to your existing search

| makeresults
| eval type="abc,xyzabc,abcdef,xyzabcdef"
| makemv type delim="," 
| mvexpand type
| replace "abc" with "123" in type

Or else

| makeresults
| eval type="abc,xyzabc,abcdef,xyzabcdef"
| makemv type delim="," 
| mvexpand type
| eval type=replace(type,"^abc$","123")
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

DataOrg
Builder

| eval type=replace(type,"abc","123")

this condition replaces all the pattern with abc. i want only with exact match "abc".

for example if fields value with "abcefg" it matches and getting replaced with 123

0 Karma

niketn
Legend

So try this

| eval type=replace(type,"^abc$","123")

You can also try as per previous comment.

| replace "abc" with "123" in type
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

niketn
Legend

@premranjithj, your question is not clear, please elaborate and add as much information as possible. What is the data you have (mock/dummy) along with field name? Also what is the query you have tried so far?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

DataOrg
Builder

i have list of fields
1.abc
2.bbc
3.abc
4.ggh
5.usb

if i a field has value abc its should be replaced with 123. other fields can have the data as it is.

0 Karma

niketn
Legend

Is the field name abc or the value of the field abc? If it is second case what is the field name?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

DataOrg
Builder

field name type and value is abc

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...