Splunk SPL查询问题:基于AD lookup计算status字段失败求助
SPL查询status字段生成失败的修复方案
问题定位
原查询第16行的eval status=case(identity==null, "inactive", identity!=null "active")存在两处语法逻辑错误:
- Splunk中判断字段是否为空需使用
isnull()/isnotnull()函数,直接用==null无法正确识别字段缺失状态 case函数的每个条件-结果对之间必须用逗号分隔,此处identity!=null后缺少逗号,导致语法不完整
修正后的完整查询
index=aws sourcetype="aws:cloudtrail" eventCategory=Management eventType=AwsConsoleSignin | stats max(_time) AS last_login count AS logins by userIdentity.arn | rename userIdentity.arn AS user | search user="*.com" | eval temp=split(user,":") | eval Account_number = mvindex(temp, 4) // 原代码误用未定义的temp2,一并修正 | eval usr =mvindex(temp, 5) | fields - temp | eval temp2=split(usr,"/") | eval role_type=mvindex(temp2,0) | eval role=mvindex(temp2,1) | eval user_email=mvindex(temp2,2) | eval last_login=strftime(last_login,"%c") | rename user_email AS email | lookup identity_ad email OUTPUTNEW bunit memberOf identity first last | eval status=case(isnull(identity), "inactive", isnotnull(identity), "active") | table status, first, last, identity, email, bunit, role, role_type, logins, last_login
额外修正说明
原查询第6行eval Account_number = mvindex(temp2, 4)存在变量误用:此时temp2尚未定义,应使用前面已定义的temp变量,否则会导致Account_number字段为空,已一并修正。
内容的提问来源于stack exchange,提问作者Mikeshift
相关产品推荐
相关产品推荐

