Splunk Search

How to trim the results of a field?

kranthi851
New Member

Hi

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Rex can do the job. Use this in place of the current eval command.

... | rex field=managedBy "CN=(?<manager>[^,]+)" | ...
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Rex can do the job. Use this in place of the current eval command.

... | rex field=managedBy "CN=(?<manager>[^,]+)" | ...
---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

kranthi851
New Member

Ya got it. Thanks

0 Karma