I am using this query to fetch current logged in user "|rest splunk_server=local /services/authentication/current-context | fields realname"
It displays real name as Lastname, Firstname
Now i want a nother field with value "Firstname Lastname" format
Try rex
.
... | eval name=realname | rex field=name mode=sed "s/([^,]+), (.*)/\2 \1/"
Thanks for reminding me that Sed can do this, but was originally curious about the eval way.
... | eval name=mvindex(split(realname,","),1).",".mvindex(split(realname,","),0)