Splunk Search

I have field DivionsID with data of Exe.123, how to trim this to just 123 ?

sumandevops
Engager

I have field DivionsID with data of Exe.123, how to trim this to just 123 ?

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

If you want to overwrite the field it should work;

| rex field = DivisionId "(?<DivisionId>\d+)"
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

venky1544
Builder

ideally regex should work if not you could try the replace command something like below

|makeresults |eval data="Exe.123" |replace "Exe.123" with "123" |table data

0 Karma

sumandevops
Engager

I didn't get you, please elaborate 

0 Karma

venky1544
Builder

HI Suman 

you wanted to trim the data Exe.123 to 123 right so you can either use regex like others or specifying or use the replace command 

it would be great if could share the more about the data and what command are you executing with regex 

its not helping when you say its not working or please elaborate 

 

0 Karma

sumandevops
Engager

why create a new field div_no? 

| rex filed = DivisionId " (?<DivisionId>\d+)" wouldn’t work?

 

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sumandevops,

You can use rex command, below will output a new field div_no.

| rex field=DivionsID "(?<div_no>\d+)"

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sumandevops
Engager

this is not working mate

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...