Splunk Search

How can I output only the first n characters of field value?

JohnEGones
Communicator

HI people,

I want from a query to only print out the first n-characters of the field value. So:

 

index=someIndex sourcetype=someNetworkDevice
| stats count by someField

 

 

The output goes:

 

someField

this is a strong value 1
this is a string value 1a
this is a string value 2
some other string value 1
some other string value 1a
some other string value 2
this is yet another string value 1
this is yet another string value 1a

etc.

 

 

I want to pull out say the first 10 characters in each row:

 

this is a
this is a
this is a
some other
some other
some other
this is yet
this is yet 

etc

 

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

HI @JohnEGones ,

I have some problem to understand why you're doing this!

Anyway, you can use eval substr to take only the first n chars of a field:

index=someIndex sourcetype=someNetworkDevice
| stats count by someField
| eval someField=substr(someField,1,10)

as you san see at https://docs.splunk.com/Documentation/Splunk/9.1.0/SearchReference/TextFunctions#substr.28.26lt.3Bst...

Ciao.

Giuseppe

View solution in original post

0 Karma

JohnEGones
Communicator

HI Giuseppe,

Nope you got it. Like when it's quick and easy. 

 

Thanks.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JohnEGones ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @JohnEGones ,

I have some problem to understand why you're doing this!

Anyway, you can use eval substr to take only the first n chars of a field:

index=someIndex sourcetype=someNetworkDevice
| stats count by someField
| eval someField=substr(someField,1,10)

as you san see at https://docs.splunk.com/Documentation/Splunk/9.1.0/SearchReference/TextFunctions#substr.28.26lt.3Bst...

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...