Splunk Search

multikv - remove unwanted rows from results

axsolis
Path Finder

Hi, I am successfully using multikv to parse my tabular data. However, my data has row separators and other non-intesting data that I would like to omit from the results. Is there a way to do this?

For example, The original data looks like this:

**This is data for XXXXX**

Heading1 Heading2 Heading3

-------------------------------------------
fieldA1 fieldA2 fieldA3
fieldB1
fieldB2 fieldB3
fieldC1 fieldC2
fieldC3

**This is data for XXXXX**

Heading1 Heading2 Heading3

-------------------------------------------
fieldA1 fieldA2 fieldA3
fieldB1
fieldB2 fieldB3
fieldC1 fieldC2
fieldC3

I obviously want to omit the lines starting with "**" and "--" from the results. How can I do this?

Thanks!

Tags (3)
0 Karma
1 Solution

aelliott
Motivator

axsolis
Path Finder

That worked. I just placed the regex command after the multikv and it omitted the lines I wanted from the search. Thanks!

|multikv|regex _raw="^[^(-|\*).*$].*$"

Above I remove lines starting with "-" and "*".

0 Karma

aelliott
Motivator

with slightly different regex

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...