Getting Data In

regex - Remove characters from results field.

nlisle
New Member

Hello,

I have produced a search result field which looks something along the lines of BC000000$@ab.firmakhueny.abc\ (I have obfuscated the data however they are the same category).

What I would like to create is a regex or something similar which may do the job better to remove all data before and after "000000" and to only present this field in the table created. To confirm I have replicated the original field and added in quotation marks presenting the data that we would like presented after the regex - BC"000000"$@ab.firmakhueny.abc\ .

Thank you for the support in adavance.

N.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

To extract the numeric portion into a new field, this rex command should do the job.

... | rex field=foo "(?<newfield>\d+)" | ...

To replace the entire field with just the numeric portion, try this.

... | rex field=foo mode=sed "s/([^\d]+)(\d+)(.*)/\2/" | ...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To extract the numeric portion into a new field, this rex command should do the job.

... | rex field=foo "(?<newfield>\d+)" | ...

To replace the entire field with just the numeric portion, try this.

... | rex field=foo mode=sed "s/([^\d]+)(\d+)(.*)/\2/" | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma

nlisle
New Member

Thank you for your response richgalloway. I have implemented the second rex command to replace the entire field with the six character numeric field from the initial search field however I am given this result "$2".

Thanks,
N

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Ah, sorry about that. Regex101.com and Splunk use different substitution methods. I've corrected my answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

nlisle
New Member

Thanks that worked!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...