Splunk Search

multikv - remove unwanted rows from results

axsolis
Path Finder

Hi, I am successfully using multikv to parse my tabular data. However, my data has row separators and other non-intesting data that I would like to omit from the results. Is there a way to do this?

For example, The original data looks like this:

**This is data for XXXXX**

Heading1 Heading2 Heading3

-------------------------------------------
fieldA1 fieldA2 fieldA3
fieldB1
fieldB2 fieldB3
fieldC1 fieldC2
fieldC3

**This is data for XXXXX**

Heading1 Heading2 Heading3

-------------------------------------------
fieldA1 fieldA2 fieldA3
fieldB1
fieldB2 fieldB3
fieldC1 fieldC2
fieldC3

I obviously want to omit the lines starting with "**" and "--" from the results. How can I do this?

Thanks!

Tags (3)
0 Karma
1 Solution

aelliott
Motivator

axsolis
Path Finder

That worked. I just placed the regex command after the multikv and it omitted the lines I wanted from the search. Thanks!

|multikv|regex _raw="^[^(-|\*).*$].*$"

Above I remove lines starting with "-" and "*".

0 Karma

aelliott
Motivator

with slightly different regex

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...