Splunk Search

field value is field name Defined

jcisha
Path Finder

Defined as the value of the field of the field name is possible?

ex) A_Field item is values "B_Field"
   conversion : B_Field = *

I'm looking into "command.conf" how using
i will not know. So the question is.

0 Karma

lguinn2
Legend

You might be able to do this with a macro, but I don't know how you would do it with a regular search.

More details would be helpful.

jcisha
Path Finder

Thank you! Let's test the macro function.
Answer If you have any other suggestions please.

0 Karma

jcisha
Path Finder

Field001 = "TEMP_FIELD", Field002 = "1000"  =>  TEMP_FIELD = 1000

Would like to change the format, such as the view.

0 Karma

stefandagerman
Path Finder

I think you need to try to restate your question. It may be just me, but I really don't understand what you are trying to do.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...