Splunk Search

Filter Feilds and suppress output data

Satyapv
Engager

Dear All,

We have splunk index with data like pattern and the pattern was recently changed.

{"Feild1":"DATA1","Feild2":"DATA2","Feild3":"DATA3","Feild4":"DATA4"}

We have several dashboards using previous data pattern like below.

DATA1,DATA2,DATA3,DATA4

Looking for a way to filter out or suppress {"Feild1": "Feild2":.....} using splunk query's and feed output to dashboards.

 

Kindly suggest how this can be done.

 

Thanks

 

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This looks like JSON of sorts - have you considered treating it as such?

In the meantime, you could use rex mode=sed

| rex mode=sed "s/\"Felid\d\"://g"
0 Karma

Satyapv
Engager

Hello,

 

This looks like JSON of sorts - have you considered treating it as such? - Not sure how to implement it.

 

| rex mode=sed "s/\"Felid\d\"://g" - how do we implement for multiple fields like Feild1, Field 2 etc?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Perhaps if you shared your actual events (anonymised as little as possible of course), we might be able to give more useful advise - as it stands, a generic question will usually get a generic response! 😎

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...