I'm struck with removing result fields unnecessary values:
ex: src domain
So, I want to remove (1),(2),(3) instead of replacing dot. results be like www.google.com
if anyone could help me out...
| makeresults | eval raw="(1)www(2)google(3)com"
| mvexpand raw
| rename raw AS "example"
| fields - _time
| eval newDomain=replace(example, "\(\d\)", ".")
| eval newDomain=replace(newDomain, "^.", "")
I'm not expecting only for www.google.com, for example I gave this domain but Internally I have many domains as per my results.
This is all about DNS debugging queries results which is coming along with (digits) .