Splunk Search

How to change each instance of a field search result?

atebysandwich
Path Finder

I'm doing a search for server names and will eventually extract to to a csv. However, each result comes out as one of the following


  • servername.domain: servername.domain
    servername: servername.domain
    servername: servername

How can I change the results in that particular field to be just servername? I feel like this is where regular expressions may come in to play. 

Labels (2)
Tags (1)
0 Karma
1 Solution

atebysandwich
Path Finder

I was able to figure out the issue without regex - I was looking at the wrong field. Thank you for the help, 

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| rex field=particular "\w+:(?<servername>\w+)\.)"
0 Karma

atebysandwich
Path Finder

Unfortunately that didn't work. The field results still come out the same. But I noticed they come out in a few different ways:

servername.domain: servername.domain
servername: servername.domain
servername: servername

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some sample events in a code block </> since normal pasting can alter the (white-space) formatting.

0 Karma

atebysandwich
Path Finder

I was able to figure out the issue without regex - I was looking at the wrong field. Thank you for the help, 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...