Splunk Search

Remove fixed string from multivalue field

shakermaker
Explorer

Hi,
I have a field alert which contains the following events:
“Failed Logon”
“Dropped Database”

However, sometimes the source application adds the string “Multiple - “ before it. Hence when running stats I end up with results like:
“Failed Logon” 9
Multiple - Failed Logon” 1

“Dropped Database” 2
Multiple - Dropped Database” 3

I am looking for way to remove the string “Multiple - ” from the event field. The results should look like
“Failed Logon” 10
“Dropped Database” 5

Appreciate your help!

Tags (3)
0 Karma

woodcock
Esteemed Legend

You need the replace command:

| replace "Multiple - *" with "*" in alert
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...