Splunk Search

Replace comma with the dot

lrudolph
Path Finder

Hi,

I have evaluated a field count with value 10000. Then I converted it with fieldformat to include a thousand separator to display it on a single value panel. Now I want to replace the comma with a dot, because we are in Europe. How can I do that?

I already tried this:

searchstring | stats count |
fieldformat count=tostring(count,
"commas") | rex field=count mode=sed
"s/\,/./g"

The result makes no difference - it's still as if I didn't use the rex-command.

Thanks,

Leo

Tags (1)
1 Solution

sowings
Splunk Employee
Splunk Employee

I agree that fieldformat doesn't seem to play nice. I wonder if its execution is "delayed" in that the formatting rules it dictates are only applied late (at display level). In any event, I was able to get the desired effect with this:

searchstring | stats count | eval count=tostring(count, "commas") | rex field=count mode=sed "s/,/./g"

The other answers post quoted by @lukejadamec says that commas should be locale-specific, but my own experimentation suggests that it is not. I've filed a case.

View solution in original post

sowings
Splunk Employee
Splunk Employee

I agree that fieldformat doesn't seem to play nice. I wonder if its execution is "delayed" in that the formatting rules it dictates are only applied late (at display level). In any event, I was able to get the desired effect with this:

searchstring | stats count | eval count=tostring(count, "commas") | rex field=count mode=sed "s/,/./g"

The other answers post quoted by @lukejadamec says that commas should be locale-specific, but my own experimentation suggests that it is not. I've filed a case.

lrudolph
Path Finder

Perfect! This does the trick!

0 Karma

lukejadamec
Super Champion

An older post suggests that the "commas" operator is locale specific, i.e. it should use decimals for Europe...
http://answers.splunk.com/answers/41636/tostring-commas-and-locale-specific-separators

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...