Splunk Search

Replace comma with the dot

lrudolph
Path Finder

Hi,

I have evaluated a field count with value 10000. Then I converted it with fieldformat to include a thousand separator to display it on a single value panel. Now I want to replace the comma with a dot, because we are in Europe. How can I do that?

I already tried this:

searchstring | stats count |
fieldformat count=tostring(count,
"commas") | rex field=count mode=sed
"s/\,/./g"

The result makes no difference - it's still as if I didn't use the rex-command.

Thanks,

Leo

Tags (1)
1 Solution

sowings
Splunk Employee
Splunk Employee

I agree that fieldformat doesn't seem to play nice. I wonder if its execution is "delayed" in that the formatting rules it dictates are only applied late (at display level). In any event, I was able to get the desired effect with this:

searchstring | stats count | eval count=tostring(count, "commas") | rex field=count mode=sed "s/,/./g"

The other answers post quoted by @lukejadamec says that commas should be locale-specific, but my own experimentation suggests that it is not. I've filed a case.

View solution in original post

sowings
Splunk Employee
Splunk Employee

I agree that fieldformat doesn't seem to play nice. I wonder if its execution is "delayed" in that the formatting rules it dictates are only applied late (at display level). In any event, I was able to get the desired effect with this:

searchstring | stats count | eval count=tostring(count, "commas") | rex field=count mode=sed "s/,/./g"

The other answers post quoted by @lukejadamec says that commas should be locale-specific, but my own experimentation suggests that it is not. I've filed a case.

lrudolph
Path Finder

Perfect! This does the trick!

0 Karma

lukejadamec
Super Champion

An older post suggests that the "commas" operator is locale specific, i.e. it should use decimals for Europe...
http://answers.splunk.com/answers/41636/tostring-commas-and-locale-specific-separators

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...