Splunk Search

how to remove last character of a field value from the search results

New Member

how to remove last character of a field value from the search results

0 Karma
1 Solution

Builder

Hi,

With rex you can do this

| rex field=yourfield "(?<no_last>.*)."

Hope help you

View solution in original post

0 Karma

Builder

Hi,

With rex you can do this

| rex field=yourfield "(?<no_last>.*)."

Hope help you

View solution in original post

0 Karma

New Member

thx for your reply jmallorquin, but i need more clarity on your suggestion .
Also i tried |eval field=rtrim(yourfield,"****") which helped me.

It will be great if you help me in understanding your view mentioned above.

  • Muthu
0 Karma

Builder

Sure,

With my command i match all the characters less the last one in a new field called no_last

0 Karma