Splunk Search
Highlighted

How can I merge two "inbound" values appearing under the same field?

Communicator

Hello

I have pre-parsed information coming into my Splunk instance for CISCO:ASA. I'm wondering why the field "direction" has a value of "inbound" showing up as "inbound" and "Inbound". How can I combine the two? Do I want to combine the two?....seems like it...

Thanks

Tim

0 Karma
Highlighted

Re: How can I merge two "inbound" values appearing under the same field?

SplunkTrust
SplunkTrust

There are a lot of ways to do that, if you want. For example...

[yourstanzaname]
SOURCE_KEY = direction
REGEX = (?i)inbound
DEST_KEY = direction
FORMAT = inbound
0 Karma