Splunk Cloud Platform

concatenate syntax

verifi81
Path Finder

Hi folks

I'm providing a sample of many values I have for field: username

Field: username

Value: 

Roger Smith
Bob Dole
Randy Savage

I'm trying to create another field with the EVAL command called EMAIL and placing a dot between first name and last name followed by @Anonymous.com

Basically I'm trying to get the new field like this.

Field: Email

Roger.Smith@falcon.com
Bob.Dole@falcon.com
Randy.Savage@falcon.com

What would the syntax be?

 

Thanks in advance

Labels (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@verifi81 

 

You should try something like this.

YOUR_SEARCH | eval email= replace(username," ",".")."@falcon.com" | table username email

 

Sample search.

 

| makeresults | eval _raw="
username
Roger Smith
Bob Dole
Randy Savage
" | multikv forceheader=1 | eval email= replace(username," ",".")."@falcon.com" | table username email

 

 

 

View solution in original post

0 Karma

verifi81
Path Finder

I stand corrected. It worked. Thank you!

0 Karma

verifi81
Path Finder

Hello Kamlesh,

My list of username is 1000 entries long so I won't be able to specify it like that. 

 

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@verifi81 

 

You should try something like this.

YOUR_SEARCH | eval email= replace(username," ",".")."@falcon.com" | table username email

 

Sample search.

 

| makeresults | eval _raw="
username
Roger Smith
Bob Dole
Randy Savage
" | multikv forceheader=1 | eval email= replace(username," ",".")."@falcon.com" | table username email

 

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...