Splunk Search

Extract value from multiple events that have different fields?

pmcfadden91
Path Finder

Below is my query which list about 80 events grouped by a certain ID (488e5185-42d7-4eec-bcb5-43590ae751a0).
The events have different field names for the same ID (ASAPLocateID, TransID, locate, clientLocateId domain="GLR">488e5185-42d7-4eec-bcb5-43590ae751a0</ns0:clientLocateId). How can I extract this ID and any others into a field regardless of the different host, source, or sourcetype?

index="gfs_cft_neo" OR index="gfs_sbl_al" source!="*performance*" "488e5185-42d7-4eec-bcb5-43590ae751a0"| reverse | streamstats window=1 global=f current=t first(source) as p_source count as Transition | eval transition_time = if(p_source == source, _time, -1 ) | where transition_time &gt; -1 | streamstats count as Transition | delta transition_time AS transition_duration | rex field=source ".*/(?&lt;Component&gt;.*).log"| table Transition, Component, transition_duration

0 Karma
1 Solution

woodcock
Esteemed Legend

With the coalesce command, like this:

index="gfs_cft_neo" OR index="gfs_sbl_al" source!="performance" "488e5185-42d7-4eec-bcb5-43590ae751a0"| eval NormalizedID=coalesce(ASAPLocateID, TransID, locate, clientLocateId)

Then you do your downstream work with NormalizedID.

View solution in original post

0 Karma

woodcock
Esteemed Legend

With the coalesce command, like this:

index="gfs_cft_neo" OR index="gfs_sbl_al" source!="performance" "488e5185-42d7-4eec-bcb5-43590ae751a0"| eval NormalizedID=coalesce(ASAPLocateID, TransID, locate, clientLocateId)

Then you do your downstream work with NormalizedID.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...