Splunk Search

Removing leading and trailing symbols from a string for numeric conversion

bonddodla
New Member

I have a field Threshold which has a value "+-5%", ">20%", "<30%" etc, which i want to convert into a number.

Could you please suggest how can i remove the leading and trailing symbols so that i can achieve the numeric value only.

Tags (1)
0 Karma
1 Solution

niketn
Legend

@bonddodla try the following rex command on your Threshold field

| rex field="Threshold" "(?<Threshold>\d+)"

Following is a run anywhere example based on sample data provided in the question

| makeresults
| eval Threshold="+-5%,>20%,<30%"
| makemv Threshold delim=","
| mvexpand Threshold
| rex field="Threshold" "(?<Threshold>\d+)"
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

bonddodla
New Member

Thanks. It worked

0 Karma

niketn
Legend

@bonddodla try the following rex command on your Threshold field

| rex field="Threshold" "(?<Threshold>\d+)"

Following is a run anywhere example based on sample data provided in the question

| makeresults
| eval Threshold="+-5%,>20%,<30%"
| makemv Threshold delim=","
| mvexpand Threshold
| rex field="Threshold" "(?<Threshold>\d+)"
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...