<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replace string to replace entire Message field with another message for specific EventCode?? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512276#M143671</link>
    <description>&lt;P&gt;thank you!!! This worked&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 07:19:43 GMT</pubDate>
    <dc:creator>priya0709</dc:creator>
    <dc:date>2020-08-04T07:19:43Z</dc:date>
    <item>
      <title>Replace string to replace entire Message field with another message for specific EventCode??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512201#M143638</link>
      <description>&lt;P&gt;My query searches for (Eventcode=509 OR EventCode=118) and generates output (host, Time, EventCode, Task category, Mesaage)&lt;/P&gt;&lt;P&gt;Is it possible to use REPLACE to replace entire message field with another message associated with the EventCode??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 19:03:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512201#M143638</guid>
      <dc:creator>priya0709</dc:creator>
      <dc:date>2020-08-03T19:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: Replace string to replace entire Message field with another message for specific EventCode??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512208#M143641</link>
      <description>&lt;P&gt;Use some conditional logic combined with an eval to get it done&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| eval Message=if(Eventcode=509 OR EventCode=118,"Insert new message here",Message)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 19:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512208#M143641</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-08-03T19:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Replace string to replace entire Message field with another message for specific EventCode??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512276#M143671</link>
      <description>&lt;P&gt;thank you!!! This worked&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 07:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512276#M143671</guid>
      <dc:creator>priya0709</dc:creator>
      <dc:date>2020-08-04T07:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Replace string to replace entire Message field with another message for specific EventCode??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512284#M143672</link>
      <description>&lt;P&gt;My query searches for eventcode and displays (host, time, task category, message) i want to use some color to highlight all &amp;nbsp;same hosts generating multiple eventcode??&lt;/P&gt;&lt;P&gt;please help with the query&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 07:23:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512284#M143672</guid>
      <dc:creator>priya0709</dc:creator>
      <dc:date>2020-08-04T07:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Replace string to replace entire Message field with another message for specific EventCode??</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512383#M143706</link>
      <description>&lt;P&gt;If my solution worked, can you accept it rather than your own?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 14:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Replace-string-to-replace-entire-Message-field-with-another/m-p/512383#M143706</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-08-04T14:08:59Z</dc:date>
    </item>
  </channel>
</rss>

