Splunk Search

Adding delimiter to a field values

Laxman24
Explorer

Hi all,

I need some help in creating a new field,

I have a field like following

Field 1
AABBCCDDEEFF
AAAABBBBCCCC

 

Id like to make a new field and the values become :

AA-BB-CC-DD-EE-FF
AA-AA-BB-BB-CC-CC

 

could someone help me with this?

Thanks in advance!

Labels (1)
1 Solution

ITWhisperer
Ultra Champion
| rex mode=sed "s/(?<pair>\w{2})/\1-/g s/-$//g"

View solution in original post

ITWhisperer
Ultra Champion
| rex mode=sed "s/(?<pair>\w{2})/\1-/g s/-$//g"

View solution in original post

Laxman24
Explorer

Thank you!!!! 🙂 it works

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!