Splunk Enterprise

How to remove beginning of a fieldname(prefix)?

New Member

Generally, I want to transform:


In all, I want to remove anything before character "_".

I have tried so many rex, wildcard expressions but nothing worked. Like:

| rex field=sort_index “\w{5}_(?<sort_index>\S+)”     (remove 5 characters before _ )
| rename \d+_* as *
| rename \w{5}_* as *

Could anyone please help me to solve this problem?

How does this problem come from? Originally I created a timechart.
As illustrated, the version is lexicon-graphically sorted. I want it (field: version ) to be sorted in reverse order.  But | sort -_time, -version simply did not work. So I created a new field named 'sort_index' and sort this new field. In order not to forget 'version', I combine new 'sort_index' with 'version' by adding '_' in the middle.

01_40_43.jpgNow it is in the right order: 
But I need to remove the prefix created previously.
These are the backgrounds why I want to do this work. If you have any better advice to achieve this target, please give me your suggestion.



0 Karma

Super Champion

did you look into below thread?


If this helps, give a like below.
0 Karma

Ultra Champion
| eval index=split(sort_index,"_")
| eval sort_index=mvindex(index,1)
| fields - index
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!