Splunk Search

How do I get specific words within a text?

shtom
New Member

The below table is what I get from a search on Splunk"

ActiveLoadId
Jabber_for_iOS-12.1.2.270036
Jabber_for_iOS-12.0.1.263155
Jabber_for_Android-12.5.1.276987
Jabber_for_Windows-11.9.3.60004
Jabber_for_Windows-12.5.0.22884

But what i want is to modify the output text under Field "ActiveLoadID" to see the first few characters. Example below:

ActiveLoadId
Jabber_for_iOS
Jabber_for_iOS
Jabber_for_Android
Jabber_for_Windows
Jabber_for_Windows

My current query is:

 "ActiveLoadId=Jabber_for" | rare limit=20000 ActiveLoadId

Appreciate your help!

0 Karma
1 Solution

vnravikumar
Champion

Hi @shtom

Try

your query....|rex field=ActiveLoadId "(?P<ActiveLoadId>.*)-"

View solution in original post

0 Karma

vnravikumar
Champion

Hi @shtom

Try

your query....|rex field=ActiveLoadId "(?P<ActiveLoadId>.*)-"
0 Karma

shtom
New Member

beautiful.....it worked

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...