Splunk Search

Bulk rename fields by regex pattern

Cuyose
Builder

Basically I have a bunch of fields that are coming in foo.date.blah, where date is dynamic and the foo and blah are static.

I want to basically just coalesce or bulk rename these all into a field labeled foo.blah.

Tags (4)
0 Karma

somesoni2
Revered Legend

Give this a try

Your current search giving all fool.<date>.blah type fields
| eval "foo.blah"=null() | foreach foo.*.blah [| eval "foo.blah"=coalesce('<<FIELD>>','foo.blah')]

See this runanywhere sample (instead of dates I used numbers but should work the same way for dates)

| gentimes start=-1 | eval "foo.12.blah"=1 | table foo* | append [| gentimes start=-1 | eval "foo.13.blah"=2 | table foo*]  | append [| gentimes start=-1 | eval "foo.14.blah"=3 | table foo*]
| eval "foo.blah"=null() | foreach foo.*.blah [| eval "foo.blah"=coalesce('<<FIELD>>','foo.blah')]
0 Karma

Cuyose
Builder

For whatever reason, this still is not working. Your example works, however replacing verbatim the foo and bar sections with my own data fails to parse out the information.

0 Karma

niketn
Legend

@Cuyose some sample field names and their values per event would help us assist you better.
Why you need coalesce()? What if multiple date fields are not null but are different?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Cuyose
Builder

The field names are as follows
codeDropUploadMap.20180828..qcTickets
codeDropUploadMap.20180711..qcTickets
codeDropUploadMap.20180804..qcTickets
etc.

The data contained within is a comma delimited string of id's. each row only has values for one of the columns, if any.

I used your format to do something similar with another field and it worked fine. I think it might have to do with the data within?

0 Karma

sudosplunk
Motivator

There's a possibility of doing this by rex. Can you provide some sample events?

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...