Splunk Search

Remove spaces in result of format function

BernardEAI
Communicator

I would like to make use of the format function to modify the results of a sub-search. I'm getting spaces in the output that are causing problems with my search.

I'm using CASE in the result to make the search case sensitive. My format function is:

| format "" "CASE(" "" ")" "OR name=" ""

The output of my subsearch is:

CASE( "User 1" ) OR name= CASE( "User 2" ) OR name= CASE( "User 3" ) 

The extra spaces around the search term prevents the CASE function from working. Is there any way to remove these spaces? 

Labels (1)
0 Karma
1 Solution

nickhills
Ultra Champion

This is a limitation of the the "format" command, I am not aware of anyway to prevent it adding spaces between the column/row separators/boundaries.

If my comment helps, please give it a thumbs up!

View solution in original post

nickhills
Ultra Champion

This is a limitation of the the "format" command, I am not aware of anyway to prevent it adding spaces between the column/row separators/boundaries.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...