Splunk Search

excluding a search result

moayadalghamdi
Path Finder

Hello Splunkers !

 

i have a problem here, that we're running an infra structure change and for that im getting duplicated logs

im running a search that show bytes count for users on proxy, but because of the double logs i get two usernames instead of on so for that the users column is empty

moayadalghamdi_0-1612350398509.png

moayadalghamdi_1-1612350601006.png

 

look at the image below please:

moayadalghamdi_2-1612350881699.png

 

we can see the username is duplicated, its the same user, but the old user has "d1$" more than the name.

please help me to eliminate the old user name and only fit the one in the search.

 

 

ive tried this: user!=*d1$* but the table still misses the users in columns

Labels (3)
0 Karma
1 Solution

manjunathmeti
Champion

hi @moayadalghamdi,

Use replace to replace "d1$" in user value.

index=Proxy user!="-" action="allowed" user=* | eval user=replace(user, "d1\$", "") | stats sum(bytes) as GB by src_ip, user | eval GB=GB/1024/1024/1024

 

If this reply helps you, an upvote/like would be appreciated.

View solution in original post

manjunathmeti
Champion

hi @moayadalghamdi,

Use replace to replace "d1$" in user value.

index=Proxy user!="-" action="allowed" user=* | eval user=replace(user, "d1\$", "") | stats sum(bytes) as GB by src_ip, user | eval GB=GB/1024/1024/1024

 

If this reply helps you, an upvote/like would be appreciated.

moayadalghamdi
Path Finder

Awesome !, Thanks !

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...