Splunk Search

How to remove double quotes from an event field

deev
Observer

Please find the sample event field comment

 

comment="This is  sample data  "to remove the double quote value" how to remove it?It is for a  "testing purpose" which we need to handle "

I have tried

rex field=_raw  mode=sed "s/\"//g" 

 

But after that when we apply   table  command  |table comment , giving me partial data  "This is  sample data " 

Appreciate your help

Deev

Labels (1)
Tags (1)
0 Karma

deev
Observer

2021-11-20 11:03:32.428, TEST_ID="0012345",COMMENTS="It tells me to use a "generic configuration request" form test. I went to test and searched for this string, it gave me a page called "Test configuration Request" which told me that I need to go to test to create CIs?"

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults
| eval _raw="2021-11-20 11:03:32.428, TEST_ID=\"0012345\",COMMENTS=\"It tells me to use a \"generic configuration request\" form test. I went to test and searched for this string, it gave me a page called \"Test configuration Request\" which told me that I need to go to test to create CIs?\""


| rex "COMMENTS=\"(?<comments>.*)\"$"
| eval comments=replace(comments,"\"","")
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Has the comment field already been extracted?

Can you share the complete _raw in a code block </>? (Obviously anonymising sensitive data first)

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...