Splunk Search

Removing leading and trailing symbols from a string for numeric conversion

bonddodla
New Member

I have a field Threshold which has a value "+-5%", ">20%", "<30%" etc, which i want to convert into a number.

Could you please suggest how can i remove the leading and trailing symbols so that i can achieve the numeric value only.

Tags (1)
0 Karma
1 Solution

niketn
Legend

@bonddodla try the following rex command on your Threshold field

| rex field="Threshold" "(?<Threshold>\d+)"

Following is a run anywhere example based on sample data provided in the question

| makeresults
| eval Threshold="+-5%,>20%,<30%"
| makemv Threshold delim=","
| mvexpand Threshold
| rex field="Threshold" "(?<Threshold>\d+)"
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

bonddodla
New Member

Thanks. It worked

0 Karma

niketn
Legend

@bonddodla try the following rex command on your Threshold field

| rex field="Threshold" "(?<Threshold>\d+)"

Following is a run anywhere example based on sample data provided in the question

| makeresults
| eval Threshold="+-5%,>20%,<30%"
| makemv Threshold delim=","
| mvexpand Threshold
| rex field="Threshold" "(?<Threshold>\d+)"
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...