Splunk Search

Trying to exclude a specific value from an extracted field

Path Finder

Hello all,


I am trying to exclude an specific value within a field while retaining others. Can you please let me know.


Eg values:

1) /Server/Cpu/load/Login

2) /Server/Memory/usage



These above are the values extracted form the event and I will have to remove only /Server value from the field while retaining all other values from the event.

Expected values needed:

1) /Cpu/load/Login

2) /Memory/usage

3) /Load/usage/value


Please help in getting this.


Labels (4)
0 Karma


where field is the name of the field you want the replacement done

| eval field=replace(field,"\/Server","")
0 Karma


You can do it by replace command:

| replace "/Server*" with "*"

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...