Splunk Search
Highlighted

How to remove part of a field value?

Path Finder

I have a search that gives me a bunch of fields that look like:
REBOOT=4/5/2016 9:17:19 AM
REBOOT=4/5/2016 9:12:02 AM
REBOOT=4/5/2016 8:58:28 AM

How can I remove the REBOOT= and keep the date/time with my search

0 Karma
Highlighted

Re: How to remove part of a field value?

SplunkTrust
SplunkTrust

If the "REBOOT=4/5/2016 9:17:19 AM" appear as a value for a field, you can do like htis

your base search | replace "REBOOT=*" with * in yourfieldname(s)

If this appears in the raw data, try like this

your base search | rex mode=sed "s/REBOOT=//g"

View solution in original post

Highlighted

Re: How to remove part of a field value?

Path Finder

Thanks, that's what I was looking for.

Chad

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.