Splunk Search

regular expression to transformation

tdthorwald
Explorer

Hello,

In my linux data, two versions of the same hostname have turned up.
and .local.
Now I have been able to change the host field using both

eval host=replace(host, ".local", "")

and

rex mode=sed field=host "s/.local//g"

at searchtime, but I'm having issues setting up a field transformation.

What do I fill in? These are my guesses...

Destination app: search
Name: remove .local
Type: regex-based

Regular expression: ".local(?\S+)" <-- something like this?

Format: Big questionmark
Source Key: host?

Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...