How to remove beginning of a fieldname(prefix)?

Generally, I want to transform:


In all, I want to remove anything before character "_".

I have tried so many rex, wildcard expressions but nothing worked. Like:

| rex field=sort_index “\w{5}_(?<sort_index>\S+)”     (remove 5 characters before _ )
| rename \d+_* as *
| rename \w{5}_* as *

Could anyone please help me to solve this problem?

How does this problem come from? Originally I created a timechart.
As illustrated, the version is lexicon-graphically sorted. I want it (field: version ) to be sorted in reverse order.  But | sort -_time, -version simply did not work. So I created a new field named 'sort_index' and sort this new field. In order not to forget 'version', I combine new 'sort_index' with 'version' by adding '_' in the middle.

01_40_43.jpgNow it is in the right order: 
But I need to remove the prefix created previously.
These are the backgrounds why I want to do this work. If you have any better advice to achieve this target, please give me your suggestion.



did you look into below thread?


| eval index=split(sort_index,"_")
| eval sort_index=mvindex(index,1)
| fields - index
