Splunk Search

Replacing Field Value

beepbop
Explorer

Hello, I have some field values which I am unable to replace with the 'replace' command in the csv file. I have Power States of servers which are Powered On and Powered Off and there are some fields which have both powered on and powered off status like:

server namePoweredOn
server namePoweredOff
server name

poweredOn

poweredOff

server namepoweredOn poweredOff suspended
server namepoweredOff PoweredOn poweredOff

 

I was able to change the field value of "poweredOn poweredOff suspended" with
|replace  "*poweredOff poweredOn suspended*" with "*Suspended*"
but when I change the command with
|replace  "*poweredOn poweredOff*" with "*PoweredOn*"
it doenst reflect. Can anyone tell me how to replace these?

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex mode=sed "s/poweredOn poweredOff suspended/Suspended/g"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...