Getting Data In

Truncate the log description after n words.

RSS_STT
Explorer

How can i Truncate the log description after 20 words in splunk and store in new field.

Labels (1)
0 Karma

batabay
Path Finder

Hello,

You can try this.

| makeresults 
| eval test = "somestring1somestring2somestring3" 
| eval new_field = if(len(test)>20,substr(test,20,len(test)),null())
0 Karma

RSS_STT
Explorer

i need to truncate the string based on word count, not based on character count.

it should save truncated string (start to 25 words) into new fields.

Current which you have provided doing on character count basis.

0 Karma

batabay
Path Finder

Okay Than, We can use regex. Can you try this ? 

| makeresults 
| eval description = "somestring1 somestring2 somestring3 somestring4 somestring5" 
| rex field=description "(?<new_field>^\S+(?:\S+\s+){20}\S+)" 
| eval new_field_replaced = replace(description,new_field,"")
| eval description = replace(description,new_field,"")

 

 

RSS_STT
Explorer

Looking good.  But this regex not handling the special character and digit. for example date 05/0/:2024 10:11:56.000 EST

0 Karma

batabay
Path Finder

I couldn't exactly understand what you're not doing with the timestamp. There are many different ways to extract the timestamp from the log. If you want to capture this field additionally, you can use \S+\s\S+.

There is example regex;

^\S+\s+\S+\s\w+\s(\S+(?:\S+\s+){1}\S+)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...