Splunk Search

help on a text comparison fonction

jip31
Motivator

Hi

I need to compare two fields from the text characters of these two fields
So I need to do something like this
where toto <> tata
The problem I have is the text one field is never exactly the same than in other field
It means that either the fields are really different and in this case I want to display the events nor the fields are almost the same
For example, if I have in one field called "spring" and in the othe field "spring - winter" I want to consider that these fields are the same because there is spring in both
Is there a solution to do this please?

Tags (1)
0 Karma
1 Solution

wmyersas
Builder

You might try something like:

| eval toto=upper(toto)
| eval tata=upper(tata)
| where match(toto,'tata') OR match(tata,'toto')

This should do a match() compare between the value of toto and the value of tata (using tata as a regex), and vice versa

Feel free to extrapolate from there how you might like to go

View solution in original post

0 Karma

wmyersas
Builder

You might try something like:

| eval toto=upper(toto)
| eval tata=upper(tata)
| where match(toto,'tata') OR match(tata,'toto')

This should do a match() compare between the value of toto and the value of tata (using tata as a regex), and vice versa

Feel free to extrapolate from there how you might like to go

0 Karma

Anantha123
Communicator

If the values in fields are constant then you may use rex , extract the required values from fields and compare it .

0 Karma

adonio
Ultra Champion

to be clear, do you wish to do text comparison to values or to fields?
can you share some sample data?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...