Splunk Search

How to customize length of value with an added prefix?

nolejj
Explorer

Hello Community,

I would like to add trailing zeros in front of a value, but only display 5 characters for the value. In addition, I would want to add a prefix of "ABC-". I have no issue with the prefix, but the zeros I would need assistance. I could add 4 zeros in front of the value and then trim the value for displaying last 5 characters, but I wanted to see the cleanest way to accomplish. Examples below.

Value = 876

I would like the new value to be ABC-00875.

Value = 1678

I would like the new value to be ABC-01678.

Value = 5

I would like the new value to be ABC-00005.

 

Thanks,

Joe

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try the printf function.

| eval Value=printf("ABC-%05d", Value)
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try the printf function.

| eval Value=printf("ABC-%05d", Value)
---
If this reply helps you, Karma would be appreciated.
0 Karma

nolejj
Explorer

Thank you. Short and nice. 🙂

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...