Knowledge Management

extract host name from field

splunkuseradmin
Path Finder

Hi everybody

I wanted to extract all hostname from this field "local_address" and save in a new field call "host" so that i only get the hostnames after "@"
I believe we can do it by "search | spath | rex field=local_address "@(?P[^-]+)"| stats count by _time host"
please corerct this.
below is the exact field

local_address
[email protected]
[email protected]
thanks

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

You can try below search

<yourBaseSearch>
| spath
| rex field=local_address "\@(?<ext_host>[^\h]*)"
| stats count by ext_host,_time

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

You can try below search

<yourBaseSearch>
| spath
| rex field=local_address "\@(?<ext_host>[^\h]*)"
| stats count by ext_host,_time
0 Karma

harsmarvania57
Ultra Champion

If local_address is multi-valued field then you can try below query

<yourBaseSearch>
| spath
| rex field=local_address "\@(?<ext_host>[^\v]*)" max_match=0
| mvexpand ext_host
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI &#43; Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...