Splunk Search

Value of field whose name is value of another field

mrabbitt
Engager

Is there a way get the value of a field whose name is the value of another field in a Splunk search?

e.g. I have a field conv_type with value "SARUSD", and there's another field named "SARUSD". I ant to set conv_value to the value of the field whose name is the value of conv_type (SARUSD).

Thanks.

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't think there is a way to do this out of the box, but it would not be too hard to write a custom search command that would do this.

0 Karma

mrabbitt
Engager

Yeah. I was hoping there was some magic syntax that I couldn't find in the documentation (like eval conv_value=${conv_type} or something), but can write a command to do it. Thanks.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...