Splunk Search

Remove extra fields

keyu921
Explorer

I search the syntax and find Account_Domain result contains two column. How can I result first column so that I left ALPHA??

ALPHA

Labels (1)
Tags (1)
0 Karma
1 Solution

maityayan1996
Path Finder

| eval Account_Domain=mvindex( Account_Domain,0)

Use this one it will take the 1st column.

View solution in original post

0 Karma

maityayan1996
Path Finder

| eval Account_Domain=mvindex( Account_Domain,0)

Use this one it will take the 1st column.

View solution in original post

0 Karma

keyu921
Explorer

Thanks it works

0 Karma

maityayan1996
Path Finder

You are welcome. Happy Splunking !!!

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!