Getting Data In

Splunk Lastname firstname formating


I am using this query to fetch current logged in user "|rest splunk_server=local /services/authentication/current-context | fields realname"
It displays real name as Lastname, Firstname
Now i want a nother field with value "Firstname Lastname" format

0 Karma


Try rex.

... | eval name=realname | rex field=name mode=sed "s/([^,]+), (.*)/\2 \1/"
If this reply helps you, an upvote would be appreciated.

Path Finder

Thanks for reminding me that Sed can do this, but was originally curious about the eval way.

0 Karma

Ultra Champion
... | eval name=mvindex(split(realname,","),1).",".mvindex(split(realname,","),0)
0 Karma