Splunk Search

extend a field value

Explorer

hello,
i want to extend a number field to a defined length like:

1324 to 001234
45678 to 045678

How could i do that on a simple way?

Thanks

Tags (2)
0 Karma
1 Solution

Ultra Champion

Assuming that you have a field num_field that needs to be zero-padded into 6 characters, and that the value of the field does not exceed 999999;

eval num_field = "000000" . num_field | eval num_field = substr(num_field, -6)

/K

View solution in original post

0 Karma

Explorer

Hi,
yes it works.

Thanks

0 Karma

Ultra Champion

Assuming that you have a field num_field that needs to be zero-padded into 6 characters, and that the value of the field does not exceed 999999;

eval num_field = "000000" . num_field | eval num_field = substr(num_field, -6)

/K

View solution in original post

0 Karma