Splunk Search

How can I use abstract command

tkdguq0110
Path Finder

How can I use abstract command?

My query is

| makeresults

| eval test = " 123456789

123

456"

| abstract maxlines=1

 This query shoud be 

"test = 123456789" I think..

But whole charecter is shown

Am I wrong understand?..

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Extending Splunk AI Assistant for SPL to Splunk Enterprise customers!

Howdy Splunk Community! It’s an exciting day here at Splunk – Splunk AI Assistant for SPL version 1.3.0 is now ...

Developer Spotlight with Qmulos

Qmulos: Building a Next-Level Cybersecurity Business through Splunk Apps Qmulos started as a scrappy startup ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...