Splunk Search

Can you help me with my regex extraction of a field?

Explorer

Hello Friends,

I have the following issue

I have two types of logs: A & B

A & B are from the same Index, have the same source type and same source (wish of the Client)

BUT they differ in two aspects:
1) the one contains the value "aaa" and the another "bbb"
2) log A has the structure FIELDNAME=VALUE
log B has the structure FIELDNAME = VALUE\

since they belong to the same sourcetype i have no idea how to delete this \ after the value

Please help

0 Karma

SplunkTrust
SplunkTrust

@alex_kh,

Try

your search |rex mode=sed field=FIELDNAME "s/\\\$//"
0 Karma

SplunkTrust
SplunkTrust

@alex_kh, Does it work for you?

0 Karma