Splunk Search

i want to match the text "followed the escaped error:" and remove the following text till the delimiter dot. it should cut other fields

DataOrg
Builder

followed the escaped error: "An error has happened executing a dash statement. hello good morning
followed the escaped error: "6g is not a valid for Value of the statement. happy morning

0 Karma
1 Solution

dineshraj9
Builder

Can you try replace command -

E.g.

| makeresults | eval text="followed the escaped error: \"An error has happened executing a dash statement. hello good morning" | eval text=replace(text,"\:[^\.]+","")

View solution in original post

woodcock
Esteemed Legend

Like this:

| makeresults 
| eval text="followed the escaped error: \"An error has happened executing a dash statement. hello good morning" 
| rex field=text mode=sed "s/\:[^\.]+//"

dineshraj9
Builder

Can you try replace command -

E.g.

| makeresults | eval text="followed the escaped error: \"An error has happened executing a dash statement. hello good morning" | eval text=replace(text,"\:[^\.]+","")

DataOrg
Builder

it should not cut other following fields only it should till dot

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...