This app allows you to apply fuzzy logic to lookups from your search result fields for near-matches. Use cases include:
search | fuzzylookup [ prefix=<string> ] [ addmetrics=[True|False] ] [ lookupfilter=<kvpairs> ] [ mask=<regex> ] [ delete=<regex> ] <lookup-table-name> ( <lookup-field> [AS <event-field>] ) [ OUTPUT | OUTPUTNEW (<lookup-destfield> [AS <event-destfield>] ) ... ]
Cross-reference your search fields against lookup data for non-exact matches, with the fields from the lookup entry/entries with the best score being appended to the event.
lookupfilter="LookupField1=\"local admin\" Lookupfield2=\"*@$email_domain$\""
Description: Text to prefix all output field names with. Helpful for applying to every lookup field without aliasing each one.
Description: Add fuzzy match metrics to each result (score, matching characters, similarity score, consecutive match length).
Syntax: lookupfilter="<lookup_field>=\"lookup_value\" <lookup_field>=\"$event_field$\""
Description: Filter for data in the specified lookup to reduce the number of comparisons
Syntax: mask="<regular expression>"
Description: Mask pattern for both compared sets of values. Masks the regex matched text before comparing.
Syntax: delete="<regular expression>"
Description: Deletion pattern for both compared sets of values. Removes the regex matched text before comparing.
We love hearing your feedback and ideas for our apps. Please email your suggestions!
Check out our blog article on the topic: Gettin' Fuzzy With It.
Bug fix for addmetrics option
- Added parameter for "add_metrics" to search command.
- Updated the docs.
- Implemented bug fixes and minor edits to the search command code.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.