Splunk Search

how i can compare last 5 fields and exclude from result

saghiralmani
New Member

i want to compare if last 5 digits of user ID are same don't show in result
how it can be done

0012345
abc0012345
xyx\0012345

if the resulting values are above as a user ID, i want to check if last 5 values(12345) are same so it should not trigger in my search as a result of user ID

Tags (1)
0 Karma

harishalipaka
Motivator

hi @saghiralmani

base search . . .. |eval test=substr(user_id_field,-5) |eventstats  count by test |where count > 1
Thanks
Harish
0 Karma

renjith_nair
Legend

@saghiralmani ,

If you want to compare the extracted IDs against another value, try

|rex field=your_user_id_field "(?<extracted_id>\d{5}$)"

OR

|eval extracted_id=substr(your_user_id_field,-5)

Compare extracted_id against with the value

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...