Splunk Search

Remove spaces in result of format function

BernardEAI
Communicator

I would like to make use of the format function to modify the results of a sub-search. I'm getting spaces in the output that are causing problems with my search.

I'm using CASE in the result to make the search case sensitive. My format function is:

| format "" "CASE(" "" ")" "OR name=" ""

The output of my subsearch is:

CASE( "User 1" ) OR name= CASE( "User 2" ) OR name= CASE( "User 3" ) 

The extra spaces around the search term prevents the CASE function from working. Is there any way to remove these spaces? 

Labels (1)
0 Karma
1 Solution

nickhills
Ultra Champion

This is a limitation of the the "format" command, I am not aware of anyway to prevent it adding spaces between the column/row separators/boundaries.

If my comment helps, please give it a thumbs up!

View solution in original post

nickhills
Ultra Champion

This is a limitation of the the "format" command, I am not aware of anyway to prevent it adding spaces between the column/row separators/boundaries.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...