Splunk Search

How to remove double quotes from an event field

deev
Observer

Please find the sample event field comment

 

comment="This is  sample data  "to remove the double quote value" how to remove it?It is for a  "testing purpose" which we need to handle "

I have tried

rex field=_raw  mode=sed "s/\"//g" 

 

But after that when we apply   table  command  |table comment , giving me partial data  "This is  sample data " 

Appreciate your help

Deev

Labels (1)
Tags (1)
0 Karma

deev
Observer

2021-11-20 11:03:32.428, TEST_ID="0012345",COMMENTS="It tells me to use a "generic configuration request" form test. I went to test and searched for this string, it gave me a page called "Test configuration Request" which told me that I need to go to test to create CIs?"

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| makeresults
| eval _raw="2021-11-20 11:03:32.428, TEST_ID=\"0012345\",COMMENTS=\"It tells me to use a \"generic configuration request\" form test. I went to test and searched for this string, it gave me a page called \"Test configuration Request\" which told me that I need to go to test to create CIs?\""


| rex "COMMENTS=\"(?<comments>.*)\"$"
| eval comments=replace(comments,"\"","")
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Has the comment field already been extracted?

Can you share the complete _raw in a code block </>? (Obviously anonymising sensitive data first)

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...