Splunk Search

How do I remove all 1 and 2 character words from a field?

andrewtrobec
Motivator

Hello,
I have a string field containing many words and I would like to remove all 1 and 2 character words from it. How do I do that? If my first sentence was the field value, the resulting output would be:

have string field containing many words and would like remove all and character words from

Best regards,

Andrew

Tags (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

Add the following to your existing search:

| rex field=yourfield mode=sed "s/\b(\w{1,2})\b//g"

https://regex101.com/r/EPipoO/1

View solution in original post

FrankVl
Ultra Champion

Add the following to your existing search:

| rex field=yourfield mode=sed "s/\b(\w{1,2})\b//g"

https://regex101.com/r/EPipoO/1

andrewtrobec
Motivator

That's the one! Thank you!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...