Splunk Search

How to extract the last 5 digits in my results as a new field?

kiran331
Builder

How to extract the last 5 digits from the following results, I need last 5 digits as a new field

00022234
001234
012345
0002345

0 Karma
1 Solution

sundareshr
Legend

Assuming this is a field called numbers. Try this ... | rex field=numbers "(?<numbers>\d{5})$"

View solution in original post

0 Karma

sundareshr
Legend

Assuming this is a field called numbers. Try this ... | rex field=numbers "(?<numbers>\d{5})$"

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Seamless IT/OT Security: A Hands-On Look at the Cisco Cyber Vision Splunk Add-on

With just a few clicks, you can ingest critical OT asset details, vulnerabilities, baseline deviations, ...