Splunk Search

How to remove closing bracket "]" from my data?

R_M
Loves-to-Learn

Data looks like  src:10.124.4.151]

and i want to remove this bracket and data should look like 10.124.4.151

I am try SED and regex  but unable to solve. 

Kindly help

Labels (1)
Tags (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@R_M - Try rtrim function.

<your query>
| eval field_name=rtrim(field_name, "]")

 

I hope this helps!!!

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm supposing that you are doing this on search time? Then one option is use

... <your base query> 
| rex "src:(?<src>[^\]]+)"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...