Splunk Search

How to drop domain from results

fdevera
Path Finder

In splunk I have fully qualified sources and destinations. Example:

src=host1.mydomain.com

When I table it out I just want it to show host1 without .mydomain.com

How do I do this?

Labels (3)
0 Karma
1 Solution

saravanan90
Contributor

Try  eval src=replace(src,".mydomain.com","")

View solution in original post

efavreau
Builder

@fdevera  You could use a regular expression to create a new field for the subdomain, then call that new field in your table.

| rex field=src "(?<justthesubdomain>.+?(?=\.))"
| table justthesubdomain

 

###

If this reply helps you, an upvote would be appreciated.

saravanan90
Contributor

Try  eval src=replace(src,".mydomain.com","")

View solution in original post

.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!