How can I remove everything after the zeroes in a field with results like this '000000000'
Thanks!
Like this:
| makeresults
| eval yourField = "00000000abcde"
| rex field=yourField mode=sed "s/^(\d+).*$/\1/"
try this
| makeresults
| eval Description="000000000</ParticipantObjectQuery></ParticipantObjectIdentificat></AuditMessage[greater than sign>"
| rex field=Description "(?<Description>\d+)"
hi @chrisschum
tried the above?
I believe you need to provide better example of values, as I don't see anything after the zeros (which portion you want to remove). If your data values are like 0000ABC
and you want to change the value to 0000
, then you'd do like this (in search)
..| eval fieldnamehere=replace(fieldnamehere,"^(0+)(.+)", "\1")
OR
..| rex field=fieldnamehere mode=sed "s/^(0+)(.+)/\1/"
It took off the full result field because it has a less than and greater than sign
000000000([less than sign]/ParticipantObjectQuery[greater than sign][less than sign]/ParticipantObjectIdentification[greater than sign][less than sign]/AuditMessage[greater than sign]"