Splunk Search

How to split/extract substring before the first - from the right side of the string

keshavgupta
Engager
Spoiler
How to split/extract substring before the first - from the right side of the field on splunk search

For ex: My field hostname contains

Hostname = abc-xyz
Hostname = abc-01-def
Hostname = pqr-01

I want to see like below .

abc
abc-01
pqr

Please help me.

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "(?<host>[^\-]+)\-"
0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...

Join the Splunk Developer Program Hackathon: Splunk Build-a-thon!

The Splunk Developer Program is launching in beta, and we’re celebrating with an exciting hackathon! This is ...