Splunk Search

Help With Event Cleanup - Remove "-"

ghostdog920
Path Finder

I am having a problem with what i believe is writing a regex to clean up some events before i report on them in dashboard.  I am pulling specific security events from windows and each event should return a username and a domain.  I am getting those results, but with each, it is also returning a second data item "-".  That is throwing things off/making it look ugly and i havent had much luck ripping it out.  Hoping someone can assist and possibly explain what the solution is doing?  I tried to do an eval replace for the field where "-" is replaced with "" but then none of my events showed up so clearly that was wrong.  A sample event looks like this to help clarify what i am getting:

 

SplunkHelpEventExample.png

 

I basically need to drop the first line from both the "Account" and also "Account_Domain" so that i would only get service. and PF as values.

 

As always, help is greatly appreciated.

Labels (2)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust
| eval Account_Domain=mvindex(Account_Domain,1), Account_Name=mvindex(Account_Name,1)
————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust
| eval Account_Domain=mvindex(Account_Domain,1), Account_Name=mvindex(Account_Name,1)
————————————
If this helps, give a like below.

ghostdog920
Path Finder

So the mvindex basically says for that field, choose in this case, the 2nd value for the field as the only value for that field?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

yes, considering second value.

Account_Name and Account_Domain fields are multi value fields  and fields index start from 0 means 1st value. in our case we needed to consider second value so it would be index 1. hope its clear.

————————————
If this helps, give a like below.
Tags (1)

ghostdog920
Path Finder

It is!  Thank you so much!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...