Splunk Search

Help With Event Cleanup - Remove "-"

ghostdog920
Path Finder

I am having a problem with what i believe is writing a regex to clean up some events before i report on them in dashboard.  I am pulling specific security events from windows and each event should return a username and a domain.  I am getting those results, but with each, it is also returning a second data item "-".  That is throwing things off/making it look ugly and i havent had much luck ripping it out.  Hoping someone can assist and possibly explain what the solution is doing?  I tried to do an eval replace for the field where "-" is replaced with "" but then none of my events showed up so clearly that was wrong.  A sample event looks like this to help clarify what i am getting:

 

SplunkHelpEventExample.png

 

I basically need to drop the first line from both the "Account" and also "Account_Domain" so that i would only get service. and PF as values.

 

As always, help is greatly appreciated.

Labels (2)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust
| eval Account_Domain=mvindex(Account_Domain,1), Account_Name=mvindex(Account_Name,1)
————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust
| eval Account_Domain=mvindex(Account_Domain,1), Account_Name=mvindex(Account_Name,1)
————————————
If this helps, give a like below.

ghostdog920
Path Finder

So the mvindex basically says for that field, choose in this case, the 2nd value for the field as the only value for that field?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

yes, considering second value.

Account_Name and Account_Domain fields are multi value fields  and fields index start from 0 means 1st value. in our case we needed to consider second value so it would be index 1. hope its clear.

————————————
If this helps, give a like below.
Tags (1)

ghostdog920
Path Finder

It is!  Thank you so much!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...