I have a lookup file query as follows
| inputlookup ABCD.csv which displays the results as follows
Now how can i add a regex to display only the hostname and avoid the extra string which ever after the dot(.). I just want to apply the regex to display the result as follows
Assuming you just want to manipulate the result of the search | inputlookup ABCD.csv, try like this
| inputlookup ABCD.csv
| inputlookup ABCD.csv | eval Host=mvindex(split(Host,"."),0)
| inputlookup ABCD.csv | rex field=Host "^(?<Host>[^\.]+)"
View solution in original post