Splunk Search

help on a text comparison fonction

jip31
Motivator

Hi

I need to compare two fields from the text characters of these two fields
So I need to do something like this
where toto <> tata
The problem I have is the text one field is never exactly the same than in other field
It means that either the fields are really different and in this case I want to display the events nor the fields are almost the same
For example, if I have in one field called "spring" and in the othe field "spring - winter" I want to consider that these fields are the same because there is spring in both
Is there a solution to do this please?

Tags (1)
0 Karma
1 Solution

wmyersas
Builder

You might try something like:

| eval toto=upper(toto)
| eval tata=upper(tata)
| where match(toto,'tata') OR match(tata,'toto')

This should do a match() compare between the value of toto and the value of tata (using tata as a regex), and vice versa

Feel free to extrapolate from there how you might like to go

View solution in original post

0 Karma

wmyersas
Builder

You might try something like:

| eval toto=upper(toto)
| eval tata=upper(tata)
| where match(toto,'tata') OR match(tata,'toto')

This should do a match() compare between the value of toto and the value of tata (using tata as a regex), and vice versa

Feel free to extrapolate from there how you might like to go

0 Karma

Anantha123
Communicator

If the values in fields are constant then you may use rex , extract the required values from fields and compare it .

0 Karma

adonio
Ultra Champion

to be clear, do you wish to do text comparison to values or to fields?
can you share some sample data?

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...