Splunk Search

Bulk rename fields by regex pattern

Cuyose
Builder

Basically I have a bunch of fields that are coming in foo.date.blah, where date is dynamic and the foo and blah are static.

I want to basically just coalesce or bulk rename these all into a field labeled foo.blah.

Tags (4)
0 Karma

somesoni2
Revered Legend

Give this a try

Your current search giving all fool.<date>.blah type fields
| eval "foo.blah"=null() | foreach foo.*.blah [| eval "foo.blah"=coalesce('<<FIELD>>','foo.blah')]

See this runanywhere sample (instead of dates I used numbers but should work the same way for dates)

| gentimes start=-1 | eval "foo.12.blah"=1 | table foo* | append [| gentimes start=-1 | eval "foo.13.blah"=2 | table foo*]  | append [| gentimes start=-1 | eval "foo.14.blah"=3 | table foo*]
| eval "foo.blah"=null() | foreach foo.*.blah [| eval "foo.blah"=coalesce('<<FIELD>>','foo.blah')]
0 Karma

Cuyose
Builder

For whatever reason, this still is not working. Your example works, however replacing verbatim the foo and bar sections with my own data fails to parse out the information.

0 Karma

niketn
Legend

@Cuyose some sample field names and their values per event would help us assist you better.
Why you need coalesce()? What if multiple date fields are not null but are different?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Cuyose
Builder

The field names are as follows
codeDropUploadMap.20180828..qcTickets
codeDropUploadMap.20180711..qcTickets
codeDropUploadMap.20180804..qcTickets
etc.

The data contained within is a comma delimited string of id's. each row only has values for one of the columns, if any.

I used your format to do something similar with another field and it worked fine. I think it might have to do with the data within?

0 Karma

sudosplunk
Motivator

There's a possibility of doing this by rex. Can you provide some sample events?

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...