Splunk Search

Replacing Field Value


Hello, I have some field values which I am unable to replace with the 'replace' command in the csv file. I have Power States of servers which are Powered On and Powered Off and there are some fields which have both powered on and powered off status like:

server namePoweredOn
server namePoweredOff
server name



server namepoweredOn poweredOff suspended
server namepoweredOff PoweredOn poweredOff


I was able to change the field value of "poweredOn poweredOff suspended" with
|replace  "*poweredOff poweredOn suspended*" with "*Suspended*"
but when I change the command with
|replace  "*poweredOn poweredOff*" with "*PoweredOn*"
it doenst reflect. Can anyone tell me how to replace these?

Labels (3)
0 Karma

| rex mode=sed "s/poweredOn poweredOff suspended/Suspended/g"
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...