Splunk Search
Highlighted

Can I use regex to remove a pipe character from a string?

Communicator

Hi All,

I am having a problem with my search output. One of the results contains a pipe ( | ) - E.g. bad_domain|www.baddomain.com.

Once run, the search results are passed to a 3rd party tool that uses pipes as formatting options - This rogue pipe is being picked up as a formatting option. I would like to know how to remove, or replace, the pipe in my search results, for example:

baddomain|www.baddomain.com to baddomainwww.baddomain.com, or baddomain-www.baddomain.com.

Can anyone assist?

Tags (3)
0 Karma
Highlighted

Re: Can I use regex to remove a pipe character from a string?

Champion

try this!

(your search)|eval text=replace(text,"\|","_")

Please change TEXT to field name.

View solution in original post

0 Karma
Highlighted

Re: Can I use regex to remove a pipe character from a string?

Communicator

Worked perfectly - Thank you so very much!

0 Karma