Dashboards & Visualizations

Is it possible to remove/replace a portion of the data at search-time for better formatting and presentation?

capilarity
Path Finder

we have logs that include a host-name which is always appended by the FQDN. The FQDN is always the same and is not needed for a high level dashboard.

This makes the field too long for a cell in a table on a dashboard and messes up the formatting of the table and therefore the page.
I've amended the indexing so all new data includes an additional field of just host-name

Is it possible (at search time) to remove this for data already indexed?

"hostname.domainname.com" to become "hostname"

Thanks

Tags (4)
0 Karma
1 Solution

capilarity
Path Finder

answered my own question

what a dufus.

field extraction to create new field

been a long morning...

View solution in original post

0 Karma

vganjare
Builder

Hi,

You can try editing the field by using eval command. Following is an example:

| eval hostname=replace(hostname,"hostname.domainname.com","hostname")

Thanks!!

0 Karma

capilarity
Path Finder

Thanks for the comment, but the "hostname" portion of the FQDN is the variable.

Can use regex to extract the host but can you use regex to write the new string?

hostname="replace(hostname,"REGEXvalue.domainname.com,"REGEXvalue)

the example in the docs uses a static value as an output

... | eval n=replace(date, "^(\d{1,2})/(\d{1,2})/", "\2/\1/")

0 Karma

capilarity
Path Finder

answered my own question

what a dufus.

field extraction to create new field

been a long morning...

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...