Splunk Search

Can you help me with my regex extraction of a field?

alex_kh
Explorer

Hello Friends,

I have the following issue

I have two types of logs: A & B

A & B are from the same Index, have the same source type and same source (wish of the Client)

BUT they differ in two aspects:
1) the one contains the value "aaa" and the another "bbb"
2) log A has the structure FIELDNAME=VALUE
log B has the structure FIELDNAME = VALUE\

since they belong to the same sourcetype i have no idea how to delete this \ after the value

Please help

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@alex_kh,

Try

your search |rex mode=sed field=FIELDNAME "s/\\\$//"
Happy Splunking!
0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@alex_kh, Does it work for you?

Happy Splunking!
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>