Splunk Search

i want to match the text "followed the escaped error:" and remove the following text till the delimiter dot. it should cut other fields

DataOrg
Builder

followed the escaped error: "An error has happened executing a dash statement. hello good morning
followed the escaped error: "6g is not a valid for Value of the statement. happy morning

0 Karma
1 Solution

dineshraj9
Builder

Can you try replace command -

E.g.

| makeresults | eval text="followed the escaped error: \"An error has happened executing a dash statement. hello good morning" | eval text=replace(text,"\:[^\.]+","")

View solution in original post

woodcock
Esteemed Legend

Like this:

| makeresults 
| eval text="followed the escaped error: \"An error has happened executing a dash statement. hello good morning" 
| rex field=text mode=sed "s/\:[^\.]+//"

dineshraj9
Builder

Can you try replace command -

E.g.

| makeresults | eval text="followed the escaped error: \"An error has happened executing a dash statement. hello good morning" | eval text=replace(text,"\:[^\.]+","")

DataOrg
Builder

it should not cut other following fields only it should till dot

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...