Splunk Search

Help with regex - How to exclude multiple parentheses and slashes from a field?

jalo23
Explorer

Is there a more elegant way to do this? New to using rex & I can’t seem to strip out the multiple parentheses and slashes from a field without using replace.  (I don't have control over the data, I know it is better to strip it out first.) These do work but in some cases there are more parentheses and slashes - is there a way to strip all of them out at once, or do I need to make repeating phrases?

| rex mode=sed field=Field_A "s/\(\)/ /g"

| rex mode=sed field=Field_B "s/\(\)/ /g"

| rex mode=sed field=Field_B "s/\// /g"

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You can combine the parentheses and slash into a character class to strip them all out at once.  You will, however, need a separate rex command for each field being processed.

| rex mode=sed field=Field_A "s;[\(\)/];;g"

| rex mode=sed field=Field_B "s;[\(\)/];;g"
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You can combine the parentheses and slash into a character class to strip them all out at once.  You will, however, need a separate rex command for each field being processed.

| rex mode=sed field=Field_A "s;[\(\)/];;g"

| rex mode=sed field=Field_B "s;[\(\)/];;g"
---
If this reply helps you, Karma would be appreciated.

jalo23
Explorer

That worked great, thank you!

| rex mode=sed field=Field_A "s;[\(\)/];;g"
| rex mode=sed field=Field_A "s;[\(\)/];;g"
| rex mode=sed field=Field_A "s/\(\)/ /g"
| rex mode=sed field=Field_A "s/\// /g"
| rex mode=sed field=Field_A "s/\// /g"

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...