Splunk Search

regular expression to transformation

tdthorwald
Explorer

Hello,

In my linux data, two versions of the same hostname have turned up.
and .local.
Now I have been able to change the host field using both

eval host=replace(host, ".local", "")

and

rex mode=sed field=host "s/.local//g"

at searchtime, but I'm having issues setting up a field transformation.

What do I fill in? These are my guesses...

Destination app: search
Name: remove .local
Type: regex-based

Regular expression: ".local(?\S+)" <-- something like this?

Format: Big questionmark
Source Key: host?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...