{"id":19626,"date":"2020-08-28T20:35:23","date_gmt":"2020-08-28T20:35:23","guid":{"rendered":"https:\/\/merikebi.warrenmyers.com\/?p=19626"},"modified":"2020-08-28T20:35:23","modified_gmt":"2020-08-28T20:35:23","slug":"splunk-match-a-fields-value-in-another-field","status":"publish","type":"post","link":"https:\/\/merikebi.warrenmyers.com\/?p=19626","title":{"rendered":"splunk: match a field\u2019s value in another field"},"content":{"rendered":"<p>Had a <a href=\"https:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=Splunk\">Splunk<\/a> use-case present itself today on needing to determine if the <em>value<\/em> of a field was found in another &#8211; specifically, it&#8217;s about deciding if a lookup table&#8217;s category name for a network endpoint is &#8220;the same&#8221; as the <code>dest_category<\/code> assigned by a Forescout CounterACT appliance.<\/p>\n<p>We have &#8220;customer validated&#8221; (and we all know how reliable <em>that<\/em> kind of data can be&#8230; (<a href=\"https:\/\/antipaucity.com\/2013\/03\/18\/delivering-solutions-shipping-is-a-feature\/#.X0lBRkkpChY\">the customer is <em>always <strong>wrong<\/strong><\/em><\/a>) names for network endpoints.<\/p>\n<p>These <em>should<\/em> be &#8220;identical&#8221; to the <code>dest_category<\/code> field assigned by CounterACT &#8230; but, as we all know, &#8220;should&#8221; is a funny word.<\/p>\n<p>What I <em>tried<\/em> (that does not work) was to get <a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/ConditionalFunctions#like.28TEXT.2C_PATTERN.29\"><code>like()<\/code><\/a> to work:<\/p>\n<p><code>| eval similar=if(like(A,'%B%') OR like(B,'%A%'), \"yes\", \"no\")<\/code><\/p>\n<p>I tried a <em>slew<\/em> of variations around the theme of trying to get the value of the field to be in the match portion of the <code>like()<\/code>.<\/p>\n<p>What I ended-up doing (that <em>does<\/em> work) is this:<\/p>\n<p><code>| eval similar=if((match(A,B) OR match(B,A)), \"yes\", \"no\")<\/code><\/p>\n<p><em>That<\/em> uses the <em>value<\/em> of the second field listed to be the <a href=\"https:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=regular expression\">regular expression<\/a> clause of the <code><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/ConditionalFunctions#like.28TEXT.2C_PATTERN.29\">match()<\/a><\/code> function.<\/p>\n<p>Things you should do ahead of time:<\/p>\n<ul>\n<li>match case between the fields (I did <code><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/TextFunctions#upper.28X.29\">upper()<\/a><\/code> .. <code><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/TextFunctions#lower.28X.29\" data-type=\"URL\" data-id=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/TextFunctions#lower.28X.29\">lower()<\/a><\/code> would work as well)<\/li>\n<li>remove &#8220;unnecessary&#8221; characters &#8211; in my case, I yoinked all non-word characters with this <code><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/TextFunctions#replace.28X.2CY.2CZ.29\">replace()<\/a><\/code> <code><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/eval\">eval<\/a><\/code>: <code>| eval A=upper(replace(A,\"\\W\",\"\"))<\/code><\/li>\n<li>know that there are limitations to this comparison method\n<ul>\n<li>&#8220;BOB&#8221; will &#8216;similar&#8217; match to &#8220;BO&#8221;, but not &#8220;B OB&#8221; (hence removing non-word characters before the <code>match()<\/code>)<\/li>\n<li>&#8220;BOB&#8221; <em>is not<\/em> &#8216;similar&#8217; to &#8220;ROB&#8221; &#8211; even though, in the vernacular, both might be an acceptible shortening of &#8220;ROBERT&#8221;<\/li>\n<\/ul>\n<\/li>\n<li>if you need more complex &#8216;similar&#8217; matching, checkout the <a href=\"https:\/\/splunkbase.splunk.com\/app\/3626\/#\/details\">JellyFisher<\/a> add-on on <a href=\"http:\/\/splunkbase.splunk.com\">Splunkbase<\/a>\n<ul>\n<li>it supports <a href=\"https:\/\/en.wikipedia.org\/wiki\/Soundex\">Soundex<\/a>, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Levenshtein_distance\">Levenshtein distance<\/a>, and a variety of other comparison functions<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Thanks, also, to @trex and @The_Tick on the <a href=\"https:\/\/splunk-usergroups.slack.com\">Splunk Usergroups Slack<\/a> <a href=\"https:\/\/splunk-usergroups.slack.com\/messages\/search-help\">#search-help<\/a> channel for working me towards a solution (even though what they suggested was not the direction I ended up going).<\/p>\n<p>from antipaucity https:\/\/antipaucity.com\/2020\/08\/28\/splunk-match-a-fields-value-in-another-field\/<br \/>\nvia <a href=\"https:\/\/ifttt.com\/?ref=da&#038;site=wordpress\">IFTTT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Had a Splunk use-case present itself today on needing to determine if the value of a field was found in another &#8211; specifically, it&#8217;s about deciding if a lookup table&#8217;s category name for a network endpoint is &#8220;the same&#8221; as the dest_category assigned by a Forescout CounterACT appliance. We have &#8220;customer validated&#8221; (and we all &hellip;<br \/><a href=\"https:\/\/merikebi.warrenmyers.com\/?p=19626\" class=\"more-link pen_button pen_element_default pen_icon_arrow_double\">Continue reading <span class=\"screen-reader-text\">splunk: match a field\u2019s value in another field<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[95],"keyring_services":[],"class_list":["post-19626","post","type-post","status-publish","format-standard","hentry","category-blih","tag-antipaucity"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/19626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19626"}],"version-history":[{"count":1,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/19626\/revisions"}],"predecessor-version":[{"id":19627,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/19626\/revisions\/19627"}],"wp:attachment":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19626"},{"taxonomy":"keyring_services","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fkeyring_services&post=19626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}