Splunk Search

Urldecode _raw at index time

Ant1D
Motivator

Hi,

I am aware that it can be done at search-time via props.conf:
[sourcetype]
EVAL-_raw = urldecode(_raw)

Is it possible to urldecode(_raw) at index time in Splunk? I want to perform a urldecode on _raw with the result being assigned to the _raw which will then be indexed by Splunk.

Is there a RegEx that can decode any url?
Thanks in advance for your help.

0 Karma

woodcock
Esteemed Legend

You can use SEDCMD to transform the raw text on the way in but the only facilities to add index-time fields require values that are either a hard-coded string or a contiguous subset of the raw data.

0 Karma

micahkemp
Champion

You may want to look into using a modular input for this.

link text

Modular input use cases

Unique use cases might require a modular or scripted input. Here are some typical examples.

    Stream results from a command, such as vmstat and iostat.
    Query a database, web service, or API.
    Reformat complex data.
    Handle sensitive information more securely.
    Handle special characters in inputs.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...