<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Truncate Log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666639#M228680</link>
    <description>&lt;P&gt;I'm confused how to truncate from this log. how do I do it from props.conf or from the SPL command? Can anyone provide a solution to this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;11&amp;gt;1 2021-03-18T15:05:30.501Z abcdefghi-jajaj-b1bc07001-xb0k7.abcdefghi-user - - - [Originator@7776 kubernetes__container_name="abcdefghi-jajaj" docker__container_id="a1bbddc80312d8501f1b1ac015d525722f105a71d6521be0728e8b057066eda1" kubernetes__pod_name="abcdefghi-jajaj-b1bc07001-xb0k7" bosh_index="0" stream="stbcd" kubernetes__namespace_name="abcdefghi-develop" bosh_id="e0700d15-ca5a-1f35-8e01-bd83d3eb705a" bosh_deployment="service-instance_f08cb851-fa53-1206-0a6b-705f3fa0f301" docker_id="a1bbddc80312d" tag="kubernetes.var.log.containers.abcdefghi-user-b1bc07001-xb0k7_abcdefghi-develop_abcdefghi-user-a1bbddc80312d8501f1b1ac015d525722f105a71d6521be0728e8b057066eda1.log" instance_type="werkir"] 2021-03-18 22:05:00.210 INFO [abcdefghi-jajaj,3010acf256f7c7e0,717ea36c0d67f3da,true] 6 --- [nio-0020-exec-1] c.id.bankabcde.common.util.SplunkUtil : [LOGIN_abc]|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|uobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|sessionID=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|appVersion=ABC123|mobilePhone=ABC123|custGroup=ABC123&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;i want to cut it to something like this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[LOGIN_abc]|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|uobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|sessionID=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|appVersion=ABC123|mobilePhone=ABC123|custGroup=ABC123&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;THANKYOU&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2023 04:05:30 GMT</pubDate>
    <dc:creator>riposans</dc:creator>
    <dc:date>2023-10-30T04:05:30Z</dc:date>
    <item>
      <title>Truncate Log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666639#M228680</link>
      <description>&lt;P&gt;I'm confused how to truncate from this log. how do I do it from props.conf or from the SPL command? Can anyone provide a solution to this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;11&amp;gt;1 2021-03-18T15:05:30.501Z abcdefghi-jajaj-b1bc07001-xb0k7.abcdefghi-user - - - [Originator@7776 kubernetes__container_name="abcdefghi-jajaj" docker__container_id="a1bbddc80312d8501f1b1ac015d525722f105a71d6521be0728e8b057066eda1" kubernetes__pod_name="abcdefghi-jajaj-b1bc07001-xb0k7" bosh_index="0" stream="stbcd" kubernetes__namespace_name="abcdefghi-develop" bosh_id="e0700d15-ca5a-1f35-8e01-bd83d3eb705a" bosh_deployment="service-instance_f08cb851-fa53-1206-0a6b-705f3fa0f301" docker_id="a1bbddc80312d" tag="kubernetes.var.log.containers.abcdefghi-user-b1bc07001-xb0k7_abcdefghi-develop_abcdefghi-user-a1bbddc80312d8501f1b1ac015d525722f105a71d6521be0728e8b057066eda1.log" instance_type="werkir"] 2021-03-18 22:05:00.210 INFO [abcdefghi-jajaj,3010acf256f7c7e0,717ea36c0d67f3da,true] 6 --- [nio-0020-exec-1] c.id.bankabcde.common.util.SplunkUtil : [LOGIN_abc]|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|uobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|sessionID=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|appVersion=ABC123|mobilePhone=ABC123|custGroup=ABC123&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;i want to cut it to something like this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[LOGIN_abc]|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|uobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|sessionID=ABC123|mobilePhone=ABC123|mobilePhone=ABC123|appVersion=ABC123|mobilePhone=ABC123|custGroup=ABC123&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;THANKYOU&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 04:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666639#M228680</guid>
      <dc:creator>riposans</dc:creator>
      <dc:date>2023-10-30T04:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Truncate Log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666646#M228685</link>
      <description>&lt;P&gt;This problem is not well defined. &amp;nbsp;But before that, I would caution any data truncation in props.conf.&lt;/P&gt;&lt;P&gt;Anyway, you need to prescribe a formula/criterion you want this done. &amp;nbsp;Are you using the front part (that you discard) or the end part (that you want to preserve) to make the determination? &amp;nbsp;If front, how are you going to determine that is the front part? &amp;nbsp;If end, how are you going to determine that it is the end part? &amp;nbsp;Without giving us this information, there can be a million ways to make this specific log entry trimmed, but most of these methods will fail you in general.&lt;/P&gt;&lt;P&gt;One example to do this in the front could be:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval _raw = replace(_raw, ".*util.SplunkUtil : ", "")&lt;/LI-CODE&gt;&lt;P&gt;Here, I'm assuming that util.SplunkUtil and the spacing are fixed values.&lt;/P&gt;&lt;P&gt;One example of using the end to do the same could be&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval _raw = replace(_raw, ".*: *(\[LOGIN_\w+\]|.+)", "\1")&lt;/LI-CODE&gt;&lt;P&gt;Here, I assume that the colon and LOGIN_* in square brackets are the fixture.&lt;/P&gt;&lt;P&gt;As you can see, the combinations are infinite. &amp;nbsp;What exactly is your design?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 04:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666646#M228685</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-10-30T04:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Truncate Log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666865#M228753</link>
      <description>&lt;P&gt;thankyou so much its works for me&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 10:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Truncate-Log/m-p/666865#M228753</guid>
      <dc:creator>riposans</dc:creator>
      <dc:date>2023-10-31T10:49:34Z</dc:date>
    </item>
  </channel>
</rss>

