Splunk Search

Remove extra fields

keyu921
Explorer

I search the syntax and find Account_Domain result contains two column. How can I result first column so that I left ALPHA??

ALPHA

Labels (1)
Tags (1)
0 Karma
1 Solution

maityayan1996
Path Finder

| eval Account_Domain=mvindex( Account_Domain,0)

Use this one it will take the 1st column.

View solution in original post

0 Karma

maityayan1996
Path Finder

| eval Account_Domain=mvindex( Account_Domain,0)

Use this one it will take the 1st column.

0 Karma

keyu921
Explorer

Thanks it works

0 Karma

maityayan1996
Path Finder

You are welcome. Happy Splunking !!!

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...