Getting Data In

How to remove everything after a specific character from a field

Shashank_87
Explorer

Hi I want to remove everything after a some characters like ? OR & when they come in a field. For example -

/temp/test?csrkyyt=12334

/test1/test2&csrkyyt=7968676

Can someone help?

0 Karma

vnravikumar
Champion

Hi @Shashank_87

Check this

| makeresults 
| eval text="/temp/test?csrkyyt=12334##/test1/test2&csrkyyt=7968676" 
| makemv delim="##" text 
| mvexpand text 
| rex field=text "(?P<output>^[^(?|&)]+)"
0 Karma

manjunathmeti
Champion

You can use rex with sed to remove all characters after ? OR &.

| rex mode=sed field=FIELD_NAME "s/[&?].*//g"

gcusello
SplunkTrust
SplunkTrust

Hi @Shashank_87,
you can use the rex comman, something like this:

index=my_index
| rex field=my_field "^(?<my_field>[^\&\?]*)"
| ...

that you can test at https://regex101.com/r/f8lmIs/1 .

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...