Splunk Search

How can I split (delimit) and select only certain value?

satheeshkumar55
Engager

IP Field in IIS log is like below.

100.30.24.56,+11.44.66.778,+120.33.44.15,12.567.89.666

I want to get only the IP before first comma. (100.30.24.56 in this case). 

Tried something like below but no luck.

eval IP=split(IP,",")

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You were halfway there.  The split function returns a multi-value field.  The next step is to extract the first entry in that multi-value field.

| eval IP=split(IP,",")
| eval IP=mvindex(IP, 0)

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

satheeshkumar55
Engager

@richgalloway That worked!. Thank you. Upvoted.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You were halfway there.  The split function returns a multi-value field.  The next step is to extract the first entry in that multi-value field.

| eval IP=split(IP,",")
| eval IP=mvindex(IP, 0)

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...