Splunk Search

Bulk rename fields by regex pattern

Cuyose
Builder

Basically I have a bunch of fields that are coming in foo.date.blah, where date is dynamic and the foo and blah are static.

I want to basically just coalesce or bulk rename these all into a field labeled foo.blah.

Tags (4)
0 Karma

somesoni2
Revered Legend

Give this a try

Your current search giving all fool.<date>.blah type fields
| eval "foo.blah"=null() | foreach foo.*.blah [| eval "foo.blah"=coalesce('<<FIELD>>','foo.blah')]

See this runanywhere sample (instead of dates I used numbers but should work the same way for dates)

| gentimes start=-1 | eval "foo.12.blah"=1 | table foo* | append [| gentimes start=-1 | eval "foo.13.blah"=2 | table foo*]  | append [| gentimes start=-1 | eval "foo.14.blah"=3 | table foo*]
| eval "foo.blah"=null() | foreach foo.*.blah [| eval "foo.blah"=coalesce('<<FIELD>>','foo.blah')]
0 Karma

Cuyose
Builder

For whatever reason, this still is not working. Your example works, however replacing verbatim the foo and bar sections with my own data fails to parse out the information.

0 Karma

niketn
Legend

@Cuyose some sample field names and their values per event would help us assist you better.
Why you need coalesce()? What if multiple date fields are not null but are different?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Cuyose
Builder

The field names are as follows
codeDropUploadMap.20180828..qcTickets
codeDropUploadMap.20180711..qcTickets
codeDropUploadMap.20180804..qcTickets
etc.

The data contained within is a comma delimited string of id's. each row only has values for one of the columns, if any.

I used your format to do something similar with another field and it worked fine. I think it might have to do with the data within?

0 Karma

sudosplunk
Motivator

There's a possibility of doing this by rex. Can you provide some sample events?

0 Karma
Get Updates on the Splunk Community!

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...