Splunk Search

Remove fixed string from multivalue field

shakermaker
Explorer

Hi,
I have a field alert which contains the following events:
“Failed Logon”
“Dropped Database”

However, sometimes the source application adds the string “Multiple - “ before it. Hence when running stats I end up with results like:
“Failed Logon” 9
Multiple - Failed Logon” 1

“Dropped Database” 2
Multiple - Dropped Database” 3

I am looking for way to remove the string “Multiple - ” from the event field. The results should look like
“Failed Logon” 10
“Dropped Database” 5

Appreciate your help!

Tags (3)
0 Karma

woodcock
Esteemed Legend

You need the replace command:

| replace "Multiple - *" with "*" in alert
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...