Splunk Search

Replace a string with other 2 strings

hashsplunk
Loves-to-Learn Lots

Hi ,

I need to replace the string in a field value role_seu_458137407337_prd-sso-data-science-752-2205-compute-role"     -- >  compute-role should be replaced as below 2 other field values .

role_seu_458137407337_prd-sso-data-science-752-2205-pl

role_seu_458137407337_prd-sso-data-science-752-2205-ds

I have tried replace command compute-role WITH pl IN ad. It didnt work

What would be the solution for this .Please help 

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @hashsplunk,

Below should work;

| eval ad=replace(ad,"compute-role","pl")

 

If this reply helps you, an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...