Splunk Search

how i can compare last 5 fields and exclude from result

saghiralmani
New Member

i want to compare if last 5 digits of user ID are same don't show in result
how it can be done

0012345
abc0012345
xyx\0012345

if the resulting values are above as a user ID, i want to check if last 5 values(12345) are same so it should not trigger in my search as a result of user ID

Tags (1)
0 Karma

harishalipaka
Motivator

hi @saghiralmani

base search . . .. |eval test=substr(user_id_field,-5) |eventstats  count by test |where count > 1
Thanks
Harish
0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@saghiralmani ,

If you want to compare the extracted IDs against another value, try

|rex field=your_user_id_field "(?<extracted_id>\d{5}$)"

OR

|eval extracted_id=substr(your_user_id_field,-5)

Compare extracted_id against with the value

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...