Splunk Search

How to replace 2 different characters in the same field?

fariapm1
Explorer

Hi,

I have a csv that is imported to splunk and one of those fields has a space for the thousands and ends with  ",00",  I need it to be an integer only with numbers.

fariapm1_1-1674740198350.png

 

I can solve this this with 2 lines:

       | eval test=replace(field1,",00","")
       | eval test=replace(test," ","")

But I want to create a new field with Calculated fields. How can I do that in one line of code?

Labels (1)
Tags (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval test=replace(replace(field1,",00","")," ","")

View solution in original post

fariapm1
Explorer

Hi,

It worked. 

I've already tried that but if you notice the space has a red dot. When I tried its only the " "

fariapm1_0-1674742668161.png

 

Tks for your help!

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Given that the replace function supports regex expressions, you could try it this way:

| eval test=replace(replace(field1,",00",""),"\s","")
0 Karma

fariapm1
Explorer

In your opinion what's the most efficient ?

" " or "\s" ?

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It depends on your events - if spaces are the only type of white space used, then " " would be slightly more efficient, although improvement that might not be detectable, so if there is a possibility that other white space characters might be used, then "\s" might be safer.

0 Karma

fariapm1
Explorer

Hi,

In this case it was a new type of space that appeared in my CSV file and it's not the 1st time that this happens.

Thank you for your support !!!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval test=replace(replace(field1,",00","")," ","")
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...